Case Study 2: Data Breaches and Regulatory Requirements

profileshanowlarjqsbuz


Case Study 2: Data Breaches and Regulatory Requirements
Due Week 6 and worth 100 points 
 

The National Institute of Standards and Technology (NIST) provides an extensive amount of information, resources, and guidance on IT and information security topics. The Federal Information Security Management Act (FISMA) provides standards and guidelines for establishing information security within federal systems. However, there have been, and continues to be, numerous security incidents including data breaches within federal systems. Review the information about FISMA at the NIST Website, located at http://csrc.nist.gov/groups/SMA/fisma/index.html. Additionally, review the information, located at http://www.govtech.com/blogs/lohrmann-on-cybersecurity/Dark-Clouds-Over-Technology-042212.html, about the data breaches within government systems.
 
Select one (1) of the data breaches mentioned to conduct a case analysis, or select another based on your research, and research more details about that incident to complete the following assignment requirements.
 
Write a three to five (3-5) page paper on your selected case in which you:
  1. Describe the data breach incident and the primary causes of the data breach.
  2. Analyze how the data breach could have been prevented with better adherence to and compliance with regulatory requirements and guidelines, including management controls; include an explanation of the regulatory requirement (such as from FISMA, HIPAA, or others).
  3. Assess if there are deficiencies in the regulatory requirements and whether they need to be changed, and how they need to be changed, to mitigate further data breach incidents.
  4. Use at least three (3) quality resources in this assignment. Note: Wikipedia and similar Websites do not qualify as quality resources. 
Your assignment must follow these formatting requirements:
  • Be typed, double spaced, using Times New Roman font (size 12), with one-inch margins on all sides; references must follow APA or school-specific format. Check with your professor for any additional instructions.
  • Include a cover page containing the title of the assignment, the student’s name, the professor’s name, the course title, and the date. The cover page and the reference page are not included in the required page length. 
 

Points: 100

Case Study 2: Data Breaches and Regulatory Requirements

Criteria

 

Unacceptable

Below 60% F

Meets Minimum Expectations

60-69% D

 

Fair

70-79% C

 

Proficient

80-89% B

 

Exemplary

90-100% A

1. Describe the data breach incident and the primary causes of the data breach.

Weight: 25%

Did not submit or incompletely described the data breach incident and the primary causes of the data breach.

Insufficiently described the data breach incident and the primary causes of the data breach.

Partially described the data breach incident and the primary causes of the data breach.

Satisfactorily described the data breach incident and the primary causes of the data breach.

Thoroughly described the data breach incident and the primary causes of the data breach.

2. Analyze how the data breach could have been prevented with better adherence to and compliance with regulatory requirements and guidelines, including management controls; include an explanation of the regulatory requirement (such as from FISMA, HIPAA, or others).
Weight: 30%

Did not submit or incompletely analyzed how the data breach could have been prevented with better adherence to and compliance with regulatory requirements and guidelines, including management controls; did not submit or incompletely included an explanation of the regulatory requirement (such as from FISMA, HIPAA, or others).

Insufficiently analyzed how the data breach could have been prevented with better adherence to and compliance with regulatory requirements and guidelines, including management controls; insufficiently included an explanation of the regulatory requirement (such as from FISMA, HIPAA, or others).

Partially analyzed how the data breach could have been prevented with better adherence to and compliance with regulatory requirements and guidelines, including management controls; partially included an explanation of the regulatory requirement (such as from FISMA, HIPAA, or others).

Satisfactorily analyzed how the data breach could have been prevented with better adherence to and compliance with regulatory requirements and guidelines, including management controls; satisfactorily included an explanation of the regulatory requirement (such as from FISMA, HIPAA, or others).

Thoroughly analyzed how the data breach could have been prevented with better adherence to and compliance with regulatory requirements and guidelines, including management controls; thoroughly included an explanation of the regulatory requirement (such as from FISMA, HIPAA, or others).

3. Assess if there are deficiencies in the regulatory requirements and whether they need to be changed, and how they need to be changed, to mitigate further data breach incidents.

Weight: 30%

Did not submit or incompletely assessed if there are deficiencies in the regulatory requirements and whether they need to be changed, and how they need to be changed, to mitigate further data breach incidents.

Insufficiently assessed if there are deficiencies in the regulatory requirements and whether they need to be changed, and how they need to be changed, to mitigate further data breach incidents.

Partially assessed if there are deficiencies in the regulatory requirements and whether they need to be changed, and how they need to be changed, to mitigate further data breach incidents.

Satisfactorily assessed if there are deficiencies in the regulatory requirements and whether they need to be changed, and how they need to be changed, to mitigate further data breach incidents.

Thoroughly assessed if there are deficiencies in the regulatory requirements and whether they need to be changed, and how they need to be changed, to mitigate further data breach incidents.

4. 3 references

Weight: 5%

No references provided

Does not meet the required number of references; all references poor quality choices.

Does not meet the required number of references; some references poor quality choices.

Meets number of required references; all references high quality choices.

Exceeds number of required references; all references high quality choices.

5. Clarity, writing mechanics, and formatting requirements

Weight: 10%

More than 8 errors present

7-8 errors present

5-6 errors present

3-4 errors present

0-2 errors present

    • 10 years ago
    • 50
    Answer(4)

    Purchase the answer to view it

    blurred-text
    NOT RATED
    • attachment
      compliance_and_governance_regulations.docx

    Purchase the answer to view it

    blurred-text
    NOT RATED
    • attachment
      case_study_2-_data_breaches_and_regulatory_requirements_.docx

    Purchase the answer to view it

    blurred-text
    NOT RATED
    • attachment
      the_data_breaches.docx

    Purchase the answer to view it

    blurred-text
    NOT RATED
    • attachment
      case_study_2_data_breaches_and_regulatory_requirements.docx
    Bids(1)