final Risk Management Paper for the HealthNet company

kumarvadlamudi7
ISOL-533ResidencyWeekendFinalResaerchPaper.docx

Running head: One Station Online Store 1

One Station Online Store 2

Table of Contents Abstract 3 Executive Summary 4 Risk Assessment 5 Risk Mitigation Plan 6 Laws, treaties and conditions applying to the business 7 Business Impact Analysis (BIA) 8 Business Continuity Plan (BCP) 9 Disaster Recovery Plan (DRP) 10 Computer Incident Response Team (CIRT) 11 References 13

Abstract

The paper talks of One stop online store that is based in three cities namely; Seattle, Los Angeles as well as Sacramento. Details on risk assessment have been broadly discussed the article pertaining warehouses, computer systems and loyalty to preservation of the customer’s needs. Laws as well as coalitions have been pointed out in the article which range from ROSCA, FTCA as well as HIPAA as disused in the article. And this paper also explains about CIRT teams and their responsibilities.

One Station Online Store

Executive Summary

One station online store is an organization that is fully dedicated to satisfying their customer’s needs. The store is online based where it is accessible to a wide range of customers each with different needs. Products that are on sale in the online store are limited to goods for the elderly. The variety of products on sale at the online store include: clothes, support items for the elderly and injured, and our major product; orthopedic implants. Medical institutions, through the use of their supply chains rely upon One Station (O.S.) for the supply of specialized products to their patients. The supply of these products seems to be a simple process but can get quite complicated. Dealing with the elderly is not such a simple task and most of them are not quite acquainted with digital platforms for online shopping. Irrespective of the complications brought about by customer interactions, the store is flourishing a lot, mostly because of its nature as an online store and also due to the rare nature of the products on supply there.

O.S data centers are spread over three cities in the U.S; Seattle, Los Angeles, and Sacramento. Due to the large volumes of data that the site handles from every city, 10 computer servers have been set up in every data center. Every city among the three cities that we deal with, has one data center, hosting ten servers. For the purpose of serving our customers with effectiveness, all our physical servers run 1000 virtual servers, with each server running an average of 100 virtual servers. This is aimed at managing the different needs of the online stores without having to run dedicated servers for every single service that the store needs. Each data center has 7500 employees which assist in managing the servers and handling customer orders. In additional to the employees, O.S deals with lots of customers who purchase products from the site, and multiple vendors who deliver the needed products to the store. All these transactions are mostly done online, which is the main reason why O.S opts for virtual servers over dedicated ones.

Risk Assessment

Many threats face stores all over the country and many more threats and risks apply to online-based stores. One Station has to deal with all sorts of threats and risks on a daily basis to stay online on a daily basis (CCOHS, 2017).

The warehouses where our products after they have delivered by the vendors, are subject to a wide variety of threats. For example, physical loss of products in the store is a threat that the store faces. Burglaries, fire and natural disasters could cause all products in the warehouses to be unusable. Natural disasters apply mostly to the centers in Los Angeles, but the rest apply to all three centers. In the occurrence of such a disaster, the store would suffer large losses due to the centralized nature of its centers; that is every center keeps all its products in a single warehouse.

The computer systems on the other end are faced with many threats as all the computer systems in the world. From data loss, through breaching of customer confidentiality, to violation of the integrity of data within the site. Computer systems of every business are usually the main targets for computer hackers looking to make free money online. Cross-site scripting attacks, buffer overflow attacks, and Denial of service attacks are examples of attacks that could be launched against O.S Online Store.

Being an online store, its reputation is the greatest that it has. O.S has to make sure that whatever products they deliver to their customers meet the required standards so as to keep them loyal to the company. This is a rather complicated process because the company has to trust that the products that the vendors provide meet the expected standards. This trust can cause reputational and financial damages if violated. If a customer gets a product of low quality or the wrong product from what they asked for, they will blame the store instead of the vendors because they do not know the inner workings of the company.

Risk Mitigation Plan

The store can set a number of measures to ensure that the major resources are protected. Their customers, their computer resources, and their products. These are necessities rather than luxuries that the company needs to take into account. They are safeguards to make sure that their precious possessions stay safe.

Company faces major loses due to physical damage and stolen/loss of their products which will be in the priority lists. It is important for any organization to follow or implement security countermeasures to help keep their products safe. Securing the premises where the products are kept makes sure that physical theft of their products is an impossibility. Security guards, electric fences and computer surveillance on the warehouses are all measures to be used for securing the products. Secondly, having clear fire safeguard procedures for the employees at the store is important to prevent an eventuality that fire destroys property belonging to O.S. Installing fire extinguishers, installing sprinklers, and installing a fire alarm are all measures to be put in place to protect the company’s products from fire destruction.

Cybersecurity organizations are accessible everywhere throughout the nation, and all have the ability in the field of computer security. Such organizations ought to be acquired to complete a total security investigation of the store and offer their expert counsel on how it could be improved. Programmers incline toward organizations which are obvious objectives and would be repulsed to organizations with high-security gauges. This is an extraordinary answer for computer security dangers like DOS, cross-site scripting, and support floods.

Products delivered to the store must be confirmed and authenticated for quality measures. This will shield the store from notoriety results which may emerge from the conveyance of low-quality items. The defend measure is gone for guaranteeing that customers get the items which have an equivalent quality as they requested. The likelihood of losing the client because of low-quality measures of their items will be decreased by guaranteeing that the nature of items is true to form.

Laws, treaties and conditions applying to the business

1. The Restore Online Shopper’s Confidence Act (ROSCA) – places restrictions on the access of customer data by third parties which may in turn incur costs on the customer. The act prevents third-parties from charging a customer unless they have explicitly outlined terms of their transaction clearly and/or have clear customer permission to charge them.

2. The Computer Fraud and Abuse Act – this act makes some activities done using a computer illegal which involve unauthorized access of a computer or its resources. Hacking and fraud using computers is therefore declared illegal and punishable by the law under this Act.

3. The Health Insurance Portability and Accountability Act (HIPAA) – which is majorly functions on health information which will identified in an individual. Here is the act will apply to O.S. which is supplying orthopedic implants. When such products are purchased by a person(he/she) this act will cover the health information.

4. The Federal Trade Commission Act of 1914 (FTCA) – this act makes it illegal to use unfair methods of competition in business. The use of such methods could lead to being liable to a law suit.

Business Impact Analysis (BIA)

This is a systematic approach to know and measure the potential consequences of an interruption to the operations of a business (Rouse, 2019). The most important resources of a company need to be protected first before anything else.

Computer systems which keep business records are very crucial to an online based store such as this one. This makes it a great tool for the running of business operations. They should be the first to be brought back online in the case of a disaster happening. If the computer systems are destroyed during the disaster, the backups should be used instead. Computer backups should be done at the end of every day in the company, to ensure that eventualities which destroy the computer systems do not affect the customer and business information.

Business products which are already in their possession also need to be assigned high security priorities. The loss of the products of a business could prove to be very costly on a business. The lack of proper security measures of the physical products that a company deals with may lead to the loss of these products in the long run. Security measures to guard against such threats should be put in place to avoid such situations. If a business fails it is mostly due to improper management of products in the business or a company. In the case of the online store, the quality of its products/goods is the major criteria by which the business is evaluated by its customers. The business can therefore never compromise on the quality of its products, especially if the business is online based.

To protect any business, customer information should be confidential and integrity. Once these two are breached, the trust that customers place on an online store diminishes along with them. The trust that customers place on the businesses they conduct business with is sacred and its violation will most certainly lead to the loss of the customer.

Business Continuity Plan (BCP)

A BCP is a process that involves creating a system that prevents a disaster from happening, and restores crucial business processes into a business in case of a disaster. This plan is more of a recovery plan that it is a preventive measure. The systems that are in the operation plan of facilitating the customer get the products they get from the website are very crucial to the existence of the business (Kenton, 2019).

The products or goods that a business sells to its customers are the first ones to consider in such an eventuality. Ensuring that the channels of supply to the business are in order is the first thing to restore after a catastrophe. This ensures that the confidence that customers have in the business stays intact because customers are assured that when they want to get a product from the business, the business will have it. B2B vendors and supplies who supply their products should have plans with the business such that they are aware of emergency scenarios. In case of a disaster, vendors should be informed so that they can implement these emergency procedures. These procedures may involve the sending of emergency packages of products which they may have in reserve.

The computer systems should come in after the informing of the vendors and suppliers. The company should make sure that they get their computer systems back online, beginning with website as it is the most crucial to the business. Customer orders could be taken, even if they are not satisfied immediately. The customers could be informed that the business is undergoing maintenance and that their products will be delivered to them as soon as possible.

Communication with the customers through standard means like social media or through the website is important. It ensures that the customers are informed that the business experiencing some technical issues and that the business is working to ensure that the service is back in service. This also increases the loyalty of the business’s customers because the business was upfront with their problems.

Disaster Recovery Plan (DRP)

A disaster recovery plan (DRP) is to restore business process or system from a disaster. This DRP can be used for wide range of disaster. DRP comes into picture when disasters like hurricanes, tornadoes, floods, earthquakes and fires from any source. DRP can be used to rebuild systems after hardware or software failures. (Gibson, 2015)

This organization is located on Seattle, Los Angeles and Sacramento, in this locations Earthquakes are the most common natural disaster as known. For this reason, disaster recovery important plan that must be implemented. When disaster happened then only disaster recovery comes into picture. So, when creating a recovery plan maximum possible disaster should cover in the plan.

While creating a disaster recovery plan three keys aspects should cover. Those are Critical Business function (CBF), Maximum acceptable outage (MAO), and Recovery time objectives (RTO). The RTO should be less than or equal to MAO then only system will recover with the acceptable outage time. (Gibson, 2015)

After having recovery plan next task is, from where to recover? For this, organization has a backup storage from there data can be retrieved and business will continue. All ways having three backups storage locations are suggested, but for this organization has only two backups only selected because of cost benefit, one is physical hot site backup created at Helena, Montana and other one is warm site backup created at Seattle, WA.

Recovery plan and storage locations are fixed, now organization will assign a team. For creating best DRP, team must know network infrastructure documentation, Identifying the most critical business assets, and reviewing histories of previous disasters in the organization. With all this knowledge team can do testing of the plan and modify if required. The same team maintain and do frequent audits on DRP. When there are changes in organization same team will review and update the DRP according to new BIA.

Computer Incident Response Team (CIRT)

As a survival tactic, a business has to move on after a catastrophe. The business has to look for a way to survive. Companies which own these businesses have to be very keen on how to handle incidences as swiftly as possible. This way businesses return to serving their customers as fast as they possibly can. The kinds of businesses which have computers at the foundation of their framework, need to return to business as fast as possible.

Data breaches in computer based business are very catastrophic to the business because over 90% of their income is based on their computer systems. An online store for example; depends on its computer systems to reach their customers. In an incident where such data breaches happen, CIRT is sent to assess the incident.

Teams of the CIRT include:

An administration team for decision-making: This team will control the data access to the employees depends on which team they are working. In case of unauthorized data transfer creates any catastrophe the need to report to this team. This team will work on that incident and get the business on track.

A team of INFOSEC: This information security will be responsible for computers security. They will handle IP access and data breach via IP through firewalls. If any incident related firewalls or any data breaches like hacking this team will be responsible for recovery of business and running.

IT Staff: This information technology team is responsible for having right tools and software’s in work computers. If an issue related to work appliances software’s this team will be responsible for fixing it.

An IT Auditor – This team is responsible for conducting frequent audits in organization on timely manner so that company’s network can run smoothly. Any system maintenance issue can be reported to this team.

Security guards for physical damage assessment: Though these days digital locks are available, at least in working hours security guards required for the safety of employees, property, and to monitor cameras. Any property damage can be reported to this team for immediate action.

A lawyer for legal advice: This teams works for keeping company safe from legal issues comes from NDA policies and for making legal documentation for company. Any legal issues will be handled by this team.

A public relations specialist: This team will work on creating nice environment between the employees and customers as well as inside the company. For any escalations for the customer they can reach this team

A financial team: This team works in salary payments to employees and any salary disputes. This will also have deferent group who will work on shopping payments and refunds.

A Human Resource representative: This team is for employees’ support. If employee has any issue with a person or with any team, employee can report here. This is HR team’s responsibility to follow up with concerned team sort out that issue.

These members all assess the damage and collaborate on finding a way to get the business back on its feet as fast as possible (Techopedia, 2016). All the expertise that a business would need for the full recovery of the business, are present in the CIRT.

References

CCOHS. (2017). Risk Assessment. Retrieved from: https://www.ccohs.ca/oshanswers/hsprograms/risk_assessment.html

Gibson, Darril. (2015). Managing Risk in Information Systems, 2nd edition. Burlington, MA: Jones & Bartlett.

What Is a Disaster Recovery Plan, p (371-372).

Kenton, Will. (2019). Business Continuity Planning (BCP). Retrieved from: https://www.investopedia.com/terms/b/business-continuity-planning.asp

Rouse, M. (2019). Business impact analysis (BIA). Retrieved from: https://searchstorage.techtarget.com/definition/business-impact-analysis

Techopedia. (2016). Computer Incident Response Team (CIRT). Retrieved from: https://www.techopedia.com/definition/24135/computer-incident-response-team-cirt