adnanali p1

2
Adnan Ali HWP1 IS433-901 Analyzing the Information Security Policy for Jetsetter Inc. 1. The online security policy for Jetsetter Inc. can be found here, https://www.jetsetter.com/security-policy 2. Jetsetter Inc. is an online members-exclusive private sales company for hotels and resorts all over the world, providing frequent travelers special rates and discounts. It was acquired in 2013 by TripAdvisor, the world’s largest travel website. 3. The most positive aspects of this policy are; A. How Jetsetter protects customer information. I believe this is the most important aspect of a security policy for an online sales company. Customers are the biggest assets for these companies, especially since they don’t meet them face-to-face. It is extremely important to ensure that their information is kept secure and how it is kept secure through a detailed policy, which this does for the most part by way of PCI DSS compliance and network security protocols. B. Security tips for customers. As with all web-based services, it is important to inform customers how to protect themselves by creating secure passwords and how to safeguard their information when using public computers. C. SSL Certificate. Jetsetter uses the industry-standard SSL (Secure Sockets Layer) encryption for data transmission. This is a very important feature for web-based companies when dealing with customer access and transmitting sensitive information such as names, credit card numbers, addresses, etc. The lock icon in the address bar not only ensures a secure established connection,

Upload: yasir-r-khan

Post on 13-Sep-2015

217 views

Category:

Documents


0 download

TRANSCRIPT

Adnan Ali HWP1IS433-901

Analyzing the Information Security Policy for Jetsetter Inc.

1. The online security policy for Jetsetter Inc. can be found here, https://www.jetsetter.com/security-policy2. Jetsetter Inc. is an online members-exclusive private sales company for hotels and resorts all over the world, providing frequent travelers special rates and discounts. It was acquired in 2013 by TripAdvisor, the worlds largest travel website.3. The most positive aspects of this policy are; A. How Jetsetter protects customer information. I believe this is the most important aspect of a security policy for an online sales company. Customers are the biggest assets for these companies, especially since they dont meet them face-to-face. It is extremely important to ensure that their information is kept secure and how it is kept secure through a detailed policy, which this does for the most part by way of PCI DSS compliance and network security protocols. B. Security tips for customers. As with all web-based services, it is important to inform customers how to protect themselves by creating secure passwords and how to safeguard their information when using public computers. C. SSL Certificate. Jetsetter uses the industry-standard SSL (Secure Sockets Layer) encryption for data transmission. This is a very important feature for web-based companies when dealing with customer access and transmitting sensitive information such as names, credit card numbers, addresses, etc. The lock icon in the address bar not only ensures a secure established connection, but proves legitimacy of the website when customers prepare to do business with the company.4. A couple of recommendations for improvement to this policy would be one, adding a section regarding Human Resources Security. This would outline the information security awareness and training process for all of Jetsetters employees, as well as accountability methods and courses of action in the case of internal compliance failures. The last recommendation would be to include a section briefly explaining how customer information will be secured and backed up in case of a security breach, and taking responsibility for unauthorized transactions.