Asset Tables

profilejesus2gewd
CopyofRM_Project_Asset_Tables_1-211.docx

Risk Management Project using Clearwater Compliance IRM Analysis – First Steps

Ima Student, Course, Semester, Date

Risk Management Project using Clearwater Compliance IRM Analysis (v. 01-2021) Course TermYear – Ima Student (Replace with your course/information (e.g. CYBR7300 SP21 – Mike Whitman), then delete all instructions in italics).

The Risk Management Project will be performed using the Clearwater IRM Analysis software. The software is cloud-based and may be accessed via a Web browser (Chrome is recommended). Each student will have an assigned account and will be provided access information once the students have been registered with Clearwater by the instructor.

Each phase is designed to take you through the exact same tasks an individual conducting a risk management program for an organization would perform, using the exact same tools that are currently available. The Clearwater software is currently the leading application for healthcare information risk management in the nation and as such you will find the software manual tailored for healthcare information systems.

Begin by reading through these instructions, and the associated tutorial - available in D2L Content section. Review and/or complete the corresponding phase of this document before beginning the software component.

Clearwater Compliance, LLC Software (https://software.clearwatercompliance.com)

Be sure to place your personal information in this document header and delete everything in italics. Save as PDF, renaming it (e.g. CYBR7300-SP21_mwhitman_asset_tables.pdf) before submitting.

PART 1 –INFORMATION ASSET INVENTORY AND RANKING TABLES

1. Begin with the provided list of information assets the case organization would have and associate them with their components.

2. Complete Tables 1 and 2 in this document.

3. Remove all instructions in italics.

4. You will then use this information to add information assets to Clearwater IRM, complete the asset information form and then assign component groups for your information assets.

Then proceed to Part 2 as described in the CC|IRM tutorial (both are completed/uploaded together, as one submission).

TABLE 1 - LISTING OF INFORMATION ASSETS

Instructions for Table 1. Delete before submitting.

Complete Table 1 below specifying any information assets appropriate to the case not provided (add/remove rows as needed), the component/media, owner, type of data, RTO, and RPO, of all provided information assets, based on assumptions you derive from the case document. An information asset is any application, database, or file store that creates, stores, transmits or receives critical data, that it is important to manage the risk for. If an information asset is “unimportant” we typically won’t waste our time with it. Technically, network packets could be considered information assets, but we’re going to focus exclusively on the critical applications and databases/file stores identified in the case organization for this project.

These values will be entered into CC|IRM later in the project. For this project, all of the assets except for the NAS’ Data and the Office File Share are considered Applications with internal data. All information assets are stored on Servers and accessed by users from their Desktops. Some of the applications are considered File-Shares. All applications are backed up their rack’s NAS (External Storage) daily. Each NAS backs its application internally, and then its data to another NAS. Each NAS also backs up its data to the Cloud Backup Service Provider (Software-as-a-Service) weekly as a single encrypted file.

Component Group Options:

Components are the systems “create, receive, store, transmit or view” information assets. Essentially, they are the containers or hardware that house and interact with information assets. For this project, use the following component types:

Applications Desktops

Servers

External Storage (NAS)

File Share

Software-as-a-Service

Note: Since we’re using applications with internal databases, rather than applications that interface with external databases, we won’t use “databases” as components. Since our application/information assets interact with other applications and each other, we include “applications” as components as well.

These component types are first entered when adding assets to CC|IRM, then you will reorganize these into groups that match the actual implementation in the case organization.

For example:

Asset

Component/ Media

Data Owner

Type of Sensitive Data

RTO Tier

RPO Tier

1) Active Directory Service

Application Desktop External Storage Server (T)

CIO

Customer Confidential

1

1

2) NAS#1 Data

Application Desktop External Storage Server (I) SaaS

CIO

Customer Confidential

2

2

(Note: I’ve just added numbers for the RTO and RPO. You should put some thought into the values for your project. If you just list them all the same or they don’t make sense, it could cost you points on the project).

Data Owner: refer to the text for the definition of the data owner. While the CIO may be the data custodian for all data, they are most likely NOT the owner of non-IT data.

Type of Sensitive Data Options:

· Customer Confidential (Conf) – any data retained by the organization that has been labeled as confidential – i.e. limited in its access, distribution and use. Examples include executive meeting records; marketing and strategic plans not yet released; details of communications with and services provided to select client organizations; and company IT and InfoSec program details.

· Electronic Patient Healthcare Information (ePHI) – any data retained by the organization that contains personal medical information, including that of employees and clients. Employee health coverage information in an HR file is not ePHI for our purposes – unless it included details on the coverage such as the account number, primary care physician, etc. Most HR records would only contain the name of the coverage (e.g. Blue Cross/Blue Shield HMO), but not the details.

· Payment Card Information (PCI) – any data retained by the organization that contains payment card information such as debit/credit card numbers with expiration dates, users’ names, security codes and/or billing information.

· Personally Identifiable Information (PII) – any data retained by the organization that contains personally identifiable information that could be used to identify an individual (or steal their identity) including names with social security numbers, driver’s license numbers, addresses, phone numbers, family members.

· Student Records (FERPA) – any data retained by the organization that contains academic information regarding an individual including names with student numbers, social security numbers, courses taken, grades assigned, academic integrity/misconduct issues, financial aid and/or other PII.

ePHI and FERPA are specialized versions of PII. If a data asset has no academic or medical content, just classify it as PII. If a component group contains multiple different classified data assets, list all that it contains.

RTO Tiers Options:

“Recovery time objective (RTO) is the maximum desired length of time allowed between an unexpected failure or disaster and the resumption of normal operations and service levels. The RTO defines the point in time after a failure or disaster at which the consequences of the interruption become unacceptable.” (CC|IRM Help Menu). Refer to the text pp. 509-10 for additional discussion of this topic.

0 = less than 1 hour

1 = 1 – 2 hours

2 = 3 – 6 hours

3= 6 – 24 hours

4= 1 – 3 days

5= 3 – 5 days

RPO Tiers Options:

“A recovery point objective (RPO) is the maximum acceptable amount of data loss measured in time. It is the age of the files or data in backup storage required to resume normal operations if a computer system or network failure occurs.” (CC|IRM Help Menu). Refer to the text pp. 509-10 for additional discussion of this topic.

0 = less than 1 hour

1 = 1 – 2 hours

2 = 3 – 6 hours

3= 6 – 24 hours

4= 1 – 3 days

5= 3 – 5 days

A few Assets have been added to the table to help you get started. You will need to identify the rest on your own. Add rows as needed.

Asset

Component

Data Owner

Type of Sensitive Data

RTO

RPO

1) HRIS

Application

Desktop

Server (A)

External storage

Human Resources

PII

1

1

2) PAYROLL

Application

Desktop

Server (B)

External storage

Accounting

PII

PCI

3

3

3) Account-Master

Application

Desktop

Server (C)

External storage

Accounting

Conf

PII

2

2

4) Rehu-Nation

Application

Desktop

Server (D)

External storage

CIO

Human Resources

Conf

4

4

5) HelpMe

Application

Desktop

Server (E)

External storage

Client Support

Conf

1

1

6) Clientz

Application

Desktop

Server (F)

External storage

Client Support

Conf

1

1

7) Sell-IT

Application

Desktop

Server (G)

External storage

Accounting

PCI

4

4

8) Market-IT

Application

Desktop

Server (H)

External storage

Marketing

Conf

5

5

9) Dell Storage NAS#1

Desktop

Server (I)

External storage

SaaS

Server Operations

PII

PCI

Conf

0

0

10) NAS#1 BARS

Desktop

External storage

Saas

Server Operations

N/A

0

0

11) Develop-IT : Legacy

File Share

Server (J)

Development

Conf

3

3

12) Develop-IT : Fantastica Line

File Share

Server (K)

Development

Conf

3

3

13) Develop-IT : Destiny Line

File Share

Server (L)

Development

Conf

3

3

14) Develop-IT : Seek & Destroy

File Share

Server (M)

Development

Conf

3

3

15) Develop-IT : Hacker line

File Share

Server (N)

Development

Conf

3

3

16) Develop-IT : New title Research and development

File Share

Server (O)

Development

Conf

3

3

17) NAS #2

Desktop

Server (I)

External storage

SaaS

Server Operations

Conf

0

0

18) NAS#2 BARS

Desktop

External storage

Saas

Server Operations

Conf

0

0

19) Manage-IT

20) Webz

21) Support-IT

22) Active Directory Service

23) Domain Name Service

24) MailCall

25) Office Fileshare

26) Server X

27)

28)

29)

30)

(add rows as needed)

TABLE 2 – WEIGHTED RANKING OF INFORMATION ASSETS

Create a weighted table analysis, as described in the text, to rank all information assets from Table 1. To assist you in the calculations, you may use the Weighted Ranking of Information Assets spreadsheet provided in D2L.

1. Identify 4-5 criteria you will use to evaluate the assets identified earlier and assign weights to the criteria. Note the weights must sum to 1.0 (as in 100%).

2. Copy the complete list of assets from Table 1 into the first column of Table 2.

3. Evaluate each information asset against your criteria by assigning a value of 0 to 5 (with 5 being most critical) under each asset criterion. Use the following scale in your assignments, to answer the question: “How important is this asset with regard to this criterion?”

a. 5 - Critically important

b. 4 - Very important

c. 3 - Important

d. 2 - Somewhat important

e. 1 - A little important

f. 0 - Not important

4. Perform the calculations to determine the totals. (each cell is multiplied by its criterion’s weight, then all products are summed into the total column). Note: sample criteria weights were added to the table to illustrate function (e.g. Crit 1; .20). Replace these values with your own criteria and weights.

5. Use the following scale to convert the weighted table analysis “Total” values to Clearwater “Importance” scores. Use standard rounding (e.g. .5 and above rounded up) to select the corresponding Importance score:

a. 5 - Critically important

b. 4 - Very important

c. 3 - Important

d. 2 - Somewhat important

e. 1 - A little important

f. 0 - Not important

Row 1 provides an example of a completed row. Replace this row’s values with your own before submitting.

6. Finally sort the entire table on the Total column. When you’re finished, your number one asset (first on the list) should be the one with the largest total, and thus the highest importance. Refer to the supplemental lecture on Weighted tables for additional instructions.

Criteria 🡺

Insert Crit 1

here

Insert Crit 2

here

Insert Crit 3

here

Insert Crit 4

here

Insert Crit 5

here

Weighted Total

0-5.0

Importance

(0-5; Not Important to Critically Important)

Criteria Weight🡺

🡻Asset Name

Insert Crit 1 weight

Here

Insert Crit 2 weight

here

Insert Crit 3 weight

here

Insert Crit 4 weight

here

Insert Crit 5 weight

here

1) HRIS

3

3

4

2

3

3.00

3 – Important

2)

3)

4)

5)

6)

7)

8)

9)

10)

11)

12)

13)

14)

15)

16)

17)

18)

19)

20)

21)

22)

23)

24)

25)

26)

27)

28)

29)

30)

(add rows as needed)

Criteria Descriptions: List and describe your criteria used in Table 2 below. Then provide a detailed justification as to how and why you selected these criteria and their weights.

Format: Criterion (e.g., Impact on Profitability – this criterion is defined as _____, This criterion was selected because _____, A weight of ___ was selected for this criterion because _____.) 1.

2.

3.

4.

5.