Project: Information Security & Risk Management
Running Head: INFORMATION SECURITY AND RISK MANAGEMENT 9
ISOL 533 - Information Security and Risk Management
Student’s Name:
Professor’s Name:
Date:
EXECUTIVE SUMMARY
The Health Network Hospital has its headquarters located in Minneapolis, Minnesota with 600 employees and generates an average of $500 million annually. Furthermore, it has its branches in Portland, Oregon, and Arlington, Virginia which support combinations of collective operations with each carrying out production systems managed by respective third-party data center hosting buyers in the strategic locations near a co-location data center.
The company comprises of three major products, that is, the net exchange which securely handles electronic media message from large hospital customers and routes them to the receiving customers like clinics. HNetPay, on the other hand, is a web portal that deals with the management of safe payments and billing. HNetConnect is an online directory listing medical staffs and facilities enabling customers to choose the service of their choice as even doctors credentials are updated frequently in their respective profiles
The Information Technology in the Health Network Inc. provides information security with the following objectives;
i) Information is made accessible to only the authorized users whether externally or internally
ii) Protection of the information, as a way of maintaining credibility and integrity to the Health Network users.
iii) Ensuring training of personnel pertaining to information security
iv) Ensuring that breach of information and any suspected weaknesses are reported on time.
RISKS- THREATS- WEKNESSES WITHIN EACH DOMAIN
|
R-T-W |
Domain Impacted |
Risk Impact / Factor |
|
Risk : A user destroying data and deletes files in an organization Threat : A user downloading unknown attachment from email Weakness : A user failing to lock the company's computer with weak password
|
User Domain |
3 |
|
Risk : A user computer or devices which provide access to computer resources Threat : Stealing of assets owned by company like laptops and mobile devices Weakness : insufficient Security on Company’s Equipment
|
Workstation Domain |
1 |
|
Risk: loss of Customers Threat : production outages due to unforeseen circumstances like natural calamities. Weakness : possible weakness involves generation of alerts.
|
LAN Domain |
2 |
|
Risk: configuration errors of routers and firewall
Threat : viruses and communication outages well as DDoS Attacks Weakness : lack of Backup data due to a failure of following procedures.
|
WAN-TO- LAN DOMAIN |
2 |
|
Risk: loss of Customers Threat : production outages due to unforeseen circumstances like natural calamities. Weakness : lack of Backup data due to a failure of following procedures.
|
WAN Domain |
2 |
|
Risk : Unpermitted access of company’s information public Internet Threat : Internal threats Weakness : lack of proper control being put in place and failure to monitor Networks. |
Remote Access Domain |
2 |
|
Risk : Destruction of primary data center by fire Threat : Changes in regulatory landscape that may impact operations Weakness : insufficient processes to content changes made on regulations
|
System Application Domain |
2 |
|
Risk : Unauthorized access from Internet to corporate servers and applications Threat : Internal Threats Weakness : Failure to monitor networks |
Remote Access Domain |
1 |
|
Risk : User destroys data in the application and deletes all files she has access too. Threat : : Changes in regulatory landscape that may impact operations Weakness : Lack of proper backups in the organization |
Application Domain |
|
|
Risk : Technician (user) uses P2P file sharing on company-owned PC Threat : Employee blackmail Weakness : inserting infected USB or Flash Drive |
User Domain |
2 |
|
Risk : Hacker penetrates your IT infrastructure Threat : gains access to your internal network because default Weakness : A firewall with unnecessary ports |
LAN- WAN Domain |
1 |
|
Risk : Workstation OS has known vulnerabilities Threat : Software Vulnerabilities Weakness : A workstation Hard drive fails |
Workstation Domain |
2 |
|
Risk : The Telecommunications closet where the switches and routers reside is unlocked and open because the AC is broken. Threat : Unauthorized access in LAN workstations Weakness : LAN OS server known to have software vulnerability |
LAN Domain |
2 |
|
Risk : A server can receive DDoS or DoS attacks from internet Threat : A network outage Weakness : FTP server can allow illegal upload of software |
WAN Domain |
1 |
|
Risk : A database Server attacked by SQL injection Threat : Crippling an organization Email Server Weakness : Corporate Data server has no backups |
Application Domain |
3 |
|
Risk : A general-purpose sniffer is found on organization-controlled client PCs Threat : Loss of data Weakness : Failure of workstation Domain |
Workstation Domain |
2 |
Table 1
Health Network Inc. Laws and regulations include;
i) Offering quality standards to their patients
ii) Offering Internet-related products and services through IT-enabled systems,
References
Righthand, S., Kerr, B. B., & Drach, K. (2013). Child Maltreatment Risk Assessments: An Evaluation Guide. Hoboken: Taylor and Francis.
Rushton, R. (2006). What a week to risk it all. London: Piccadilly Press.
Tasler, Nick, Schirner, & Buck. (2015). The Impulse Factor: Why Some of Us Play It Safe and Others Risk It All. Brilliance Audio.