final Risk Management Paper for the HealthNet company
ISOL 533 - Information Security and Risk Management Risk ASSessment Plan University of the Cumberlands
Executive Summary
In this paper, Risk Management Plan has implemented on a company called Health Network Inc, which is health service organization. Health Network Inc headquarter is in Minneapolis, Minnesota. And it has two branch locations in Portland, Oregon and Arlington, Virginia. This is big company with more than 600 employees and $500 Million USD business annually.
Current risk assessment of Health Network Inc is outdated, So the plan is to create a new one. To create new risk management plan, for this it is important to identify potential risks of Heath Network Inc. Risk management plan includes evaluating the identified risks and provide mitigation actions for those risks. It requires re-evaluation of threats throughout the organization as new risks are always possible.
As every organization will have risks it is important to have risk management plan for every organization. This Risk Management Plan covers the Risks, Threats and Weaknesses of the Health Network, Inc.
Figure 1
Risks – threats – weaknesses within each domain
Below are threats as per domain.
User Domain: In user domain able to identify three main threats. Those are
1. Employee relationship gone bad – When employee relationship gone bad it reflects on the company’s product quality so always having good relation between employee is very important.
2. Nurse downloads an unknown e-mail attachment – this threat comes under PII (Personal Identity information) loss or theft, to control this kind of threats having a good access control is enough. Through this access control process System administration will give proper access to employees by this every employee will have access to the required information only.
3. A technician inserts CDs and USB hard drives with personal photos, music, and videos on organization-owned computers – this can be considered as biggest threat among three and it is work station domain threat as well, inserting personal information CDs and USB hard drives on organization owned computers will increase the chance of malware attack on the office computers. Though firewalls and antivirus are installed in the organization computers avoiding this kind of action will keep the organization information safe.
Workstation Domain: There are 4 threats in workstation domain.
1. Workstation operating system (OS) has a known software vulnerability – By using the OS systems with known software vulnerability on it will give more chance to attacker to attack company’s website. To avoid this vulnerability all the system should be always update to the current version of software and always check for new updates to avoid these.
2. Workstation browser has software vulnerability – As mentioned above, having software vulnerability is invitation for attackers, to avoid this update the software of that browser or increase firewall security on that browser.
3. Unauthorized access to organization-owned workstations – This one of the biggest risks for any organization, most of the times unauthorized access leads to data loss or business loss due to privacy policies. So unauthorized access must be avoided.
4. A technician inserts CDs and USB hard drives with personal photos, music, and videos on organization-owned computers – Same explain in user domain.
LAN Domain: There are 4 threats in LAN domain. By increasing firewall security, we avoid these threats.
1. Wireless Local Area Network (WLAN) access points are needed for LAN connectivity within a warehouse
2. Need to prevent rogue users from unauthorized WLAN access
3. LAN server OS has a known software vulnerability
4. Denial of service attack on organization’s email server – This one is threat in WAN Domain as well.
WAN-to-LAN Domain: There are 3 threats in WAN-to-LAN domain. By increasing firewall security, we avoid these threats.
1. Hacker penetrates IT infrastructure through modem bank
2. Weak ingress/egress traffic-filtering degrades performance
3. Virtual Private Network (VPN) tunneling between the remote computer and ingress/egress router
WAN Domain: There are 3 threats in WAN domain. By increasing firewall security, we avoid these threats.
1. Communication circuit outages
2. Denial of service attack on organization’s email server
3. Service provider has a major network outage
Remote Access Domain: Remote access domain has mainly 2 threats.
1. Unauthorized access from public Internet – Remote accessing organization computers from public Internet may cause virus attack or hackers attack. So better avoid remote access.
2. Remote communications from home office - As home office will not have great firewall configuration remote communication from home office also not safe.
System/Application Domain: there are 3 main threats in system application domain. Always having multiple data backups will help to mitigate below threats
1. Doctor destroys data in application, deletes all files, and gains access to internal network
2. Fire destroys primary data center
3. Loss of production data server
Risk Impact/Factor assessment for R – t – W
Risk Impact/Factor number is given as per the loss or damage to the organization. Below are the levels of Impact.
“1” is Critical: An R-T-W that impacts compliance and places the organization in a position of increased liability.
“2” is Major: An R-T-W that impacts the C-I-A of an organization’s intellectual property assets and IT infrastructure.
“3” is Minor: An R-T-W that can impact user or employee productivity or availability of the IT infrastructure
|
Risk – Threat – Weakness |
Domain Impacted |
Risk Impact / Factor |
|
Unauthorized access from public Internet |
Remote Access Domain |
1 |
|
Hacker penetrates IT infrastructure through modem bank |
LAN to WAN Domain |
2 |
|
Communication circuit outages |
WAN Domain |
1 |
|
Workstation operating system (OS) has a known software vulnerability |
Workstation Domain |
3 |
|
Denial of service attack on organization’s email server |
LAN and WAN Domain |
1 |
|
Remote communications from home office |
Remote Access Domain |
3 |
|
Workstation browser has software vulnerability |
Workstation Domain |
2 |
|
Weak ingress/egress traffic-filtering degrades performance |
LAN to WAN Domain |
1 |
|
Wireless Local Area Network (WLAN) access points are needed for LAN connectivity within a warehouse |
LAN Domain |
1 |
|
Need to prevent rogue users from unauthorized WLAN access |
LAN domain |
3 |
|
Doctor destroys data in application, deletes all files, and gains access to internal network |
System Application Domain |
2 |
|
Fire destroys primary data center |
System Application Domain |
2 |
|
Intraoffice employee romance gone bad |
User Domain |
3 |
|
Loss of production data server |
System Application Domain |
1 |
|
Unauthorized access to organization-owned workstations |
Workstation Domain |
1 |
Table 1
Compliance Laws and Regulations
Many laws and regulation exist in the United States related to information technology. For this Heath Network Inc. below laws and regulations are compliance.
1. Federal Information Security Management Act (FISMA) 2002 – From this law protecting systems and data is the responsibility of agency heads. “FISMA includes details on how to protect systems and data” (Gibson, 2015). As per this law organization must inventory systems and also must do risk assessments to categorize systems and data.
2. Health Insurance Portability and Accountability Act (HIPAA) 1996 – risk management pla must compliance with HIPAA, this law includes Identification of all health data, Storage of health data, usage of health data and Transmission of health data. CIO and Human resources department heads are responsible for these jobs. (Gibson, 2015)
References
Gibson, Darril. (2015). Managing Risk in Information Systems, 2nd edition. Burlington, MA: Jones & Bartlett.
U.S. Compliance laws, pp 58-60
Scope Example: HIPAA Compliance, pp 91