INTERNATIONAL JOURNAL OF LATEST TECHNOLOGY IN ENGINEERING,
MANAGEMENT & APPLIED SCIENCE (IJLTEMAS)
ISSN 2278-2540 | DOI: 10.51583/IJLTEMAS | Volume XIII, Issue VII, July 2024
www.ijltemas.in Page 164
Offering quality insurance products, which meet our clients’ ever-growing needs
Expanding customer access to our services through both innovative and conventional communication networks
Values
Our business values are manifold:
Trust: We also try to gain new customers and keep our long-standing customers by being reliable, honest, and consistent in
offering our services.
Knowledge: We pursue training and education so as to be in a better position to give our clients the best advice regarding
insurance coverages and other related products.
Connection: We avail ourselves to our clients across all online platforms, by telephone, and in person offering services to our
long-standing clients and reaching out for new customers who might benefit from our services.
Teamwork: We love teamwork. We consider people within the company (staff) and outside the company (clients) as one team,
which helps us to effectively offer our services.
Respect: We treat all our clients and each other with courtesy, dignity, and appreciation.
Integrity and Professionalism: We conduct ourselves with transparency and honesty in all we do. We also strive to be
responsible and courteous in our interaction with clients as well as other businesses.
Fun & Humor: They say life is never that serious. We try not to take anything too serious by ensuring that our work environment
is friendly and welcoming to our employees and customers. Being happy is part of our culture.
Commitment: We give our clients full attention, anticipate their needs, and are always upfront with our terms and conditions,
including coverage details.
II. IT Philosophy
While philosophy is broadly referred to as the study of fundamental nature of knowledge, existence, and reality, especially in the
academic realm, it can simply be considered as the ideas, values, and principles behind a phenomenon (Reijers, 2021). Therefore,
with regard to the current strategic cybersecurity plan, information technology (IT) philosophy can be considered as the guideline
principles, values, and/or ideas that influence the approach and perspective of Grayson Insurance towards IT. At Grayson
Insurance, the IT philosophy will be dictated by the fact that the company requires strong and proactive cybersecurity practices,
which align with the company’s global presence in the insurance industry. As indicated in the policy analysis phase, two
cybersecurity policies that affect our company include FISMA and GDPR. Therefore, our IT philosophy will not only take into
consideration these regulations, but also the vulnerabilities that were identified in the risk assessment phase regarding the critical
information assets, and hardware and software used at Grayson Insurance, the functions that are outsourced, the use of cloud
technology, technical solutions important to the company, the company’s bring your own devices status, and the working
arrangements at the company that might affect its cybersecurity posture.
Grayson Insurance’s IT philosophy will focus on the following matters: digital transformation, cybersecurity classification, risk
management, security controls, proactive cybersecurity, and business and IT alignment. By embracing digitalization, Grayson
Insurance intends to streamline data collection processes and prioritize frictionless methods so as to improve customer services,
while upholding security standards. Some of the services that Grayson Insurance will outsource with an aim of improving
customer services, while upholding security standards, include customer support services (helpdesk support, live chat support),
cloud service management (cloud hosting, data backup and recovery), application development and maintenance (software
development, patch management), cybersecurity services (managed security services, penetration testing), data analytics and
business intelligence, and web and mobile application development.
For instance, outsourcing helpdesk services and live chat support will ensure Grayson Insurance provides 24/7 handling of
queries and issues. Outsourcing cloud services can help in optimizing the storage of data, scalability, and ensuring that a company
complies with security protocols. Another advantage is that they provide routine data backup, helping companies with fast
recovery to avoid prolonged downtimes (Mtsweni et al., 2021).
Furthermore, as indicated in the risk analysis phase, Grayson Insurance will make use of a data classification scheme that
classifies data as personally identifiable information (PII), financial data, protected health information (PHI), intellectual property
(IP), and more. This classification will ensure that the company will comply with such relevant, industry regulations as GDPR,
Health Insurance Portability and Accountability Act (HIPAA), Sarbanes-Oxley Act (SOX), and Payment Card Industry Data
Security Standard (PCI DSS), among others.
Since Grayson Insurance is vulnerable to phishing attacks, insider threats, cyberattacks on patient records, and intellectual
property theft, some of the technical solutions that the company will adapt to ensure it is not affected by these vulnerabilities
include implementing email filtering systems, multi-factor authentication (MFA), encryption, intrusion detection systems, and