cmgt 545 prooo max

profileCnwofia
cmgt545_v1_wk5_risk_assessment_c_suite_group_tasks26sept2020v2.docx

CMGT/545v1

Risk Assessment – C-Suite Group Tasks

CMGT/545 v1

Page 2 of 2

C:\Users\djshirey\OneDrive - University of Phoenix\F_Drive\Style Guides\UPX Logos\Horizontal format\UOPX_Sig_Hor_Black_Medium.png

Risk Assessment – C-Suite Group Tasks

Research

1) Research the following items to assist in negotiating an appropriate risk assessment for Intuit, Inc.’s cloud-based applications project:

· Laws and regulations to consider when implementing security controls: In certain industries, these laws are mandatory and have legal consequences such as PCI DSS, HIPPA, FERPA, SOX, etc.

· Industry standards and what other competitors in the same business are doing, for example, “company ABC are implementing a 2-factor authentication and encryption so we’re doing it too”

2) Ensure the following items are taken into consideration when negotiating:

· The company has reasonable protections in place for security of their information system.

· Budget, time, and resources (human resources; computer, network, and system resources) are allocated appropriately and utilized efficiently. The team needs to be able to measure the project’s success by creating a measurable matrix or KPIs.

· There a balance between security and convenience that won’t interrupt day-to-day activities.

· Information security policy is approved by upper management and enforced throughout the company (with the help of the IT department).

Summary

Write a summary of your research findings.

Some of the security control and laws of the cloud can be technology and have major state and federal level issues that need to be assessed. A statute is entitled to the Family Educational Rights and Privacy Act (FERPA) and protects student educational records. There has been a significant surge of new laws and regulations passed by governments to implement security and privacy measures for companies storing information in the cloud. Wave is due to recent security breaches and the realization of how much information can be compromised—most data stored in the cloud range from personal information to confidential government intelligence. Although the most publicized breaches may be of celebrity’s compromising photographs, many other violations of medical insurance companies and credit card accounts have affected the public. It is only natural that a set of new privacy and security laws are drafted both internationally and domestically as the use of cloud computing technology expands

At Intuit, the security of our products remains a top priority. We use security safeguards to help protect the systems and the information customers and employees give to us from loss, misuse, and unauthorized alteration. We use technical, logical, and procedural measures, such as multi-factor authentication, that are designed to help detect and prevent fraud and misuse of customer information. We routinely patch our systems with security updates, and we work to protect our systems from unauthorized internal or external access using numerous commercially available computer security products, as well as internally developed security procedures and practices.

The research we have discovered leads us to implement Tripwire IP 360 it provides the necessary architecture to provide Intuit with security, compliance with regulations and scalability that the company needs to ensure security through growth. Tripwire IP360 delivers risk-based vulnerability assessment and asset discovery capabilities. These are among the top foundational controls recommended by security experts. With Tripwire IP360, you get:

· Comprehensive discovery and profiling of all network assets

· Highly scalable architecture with low network impact

· Advanced vulnerability scoring that identifies top risks

· Prioritized change results when used with Tripwire Enterprise

· Agent-based vulnerability management for superior protection

Tripwire has a proven record helping companies achieve and maintain compliance. Tripwire has extensive experience not only with SOX/COBIT but also the PCI, NERC, HIPAA and FISMA standards.

Tripwire delivers a comprehensive portfolio of integrity control, policy management, vulnerability management and log intelligence to reduce time spent on audits. It also monitors systems for any unauthorized changes and prioritizes vulnerability to ensure health data is not compromised. Organizations can correlate events with changes that impact HIPAA policies. Tripwire helps to ensure the confidentiality, integrity and availability of your electronic protected health information. Tripwire’s automated solutions allows you to continuously maintain your organization in a compliant state.

Our company has and will implement multi-factor authentication, a secure Virtual Private Network (VPN), data a rest encryption and a robust Disaster Recovery Plan (DRP) along with a Network Based and Host Based Intrusion Protection program to ensure a complete security and vulnerability management profile.

The IT department has drafted a document outlining the protective and compliance measure, that include SOX, PCI DSS and NIST requirements as the guidance for approval for upper management to adopt as policy, the plan also include computer based training requirements for the company.

Law Offices of Salar Atrizadeh April 6, 2015 https://www.internetlawyer-blog.com/cloud-computing-laws-and-regulations/

https://www.intuit.com/content/dam/intuit/intuitcom/documents/company/intuit-cr-report-2019.pdf

https://www.tripwire.com/products/tripwire-ip360/tripwire-ip360-datasheet-register/

Copyright 2020 by University of Phoenix. All rights reserved.

Copyright 2020 by University of Phoenix. All rights reserved.