Project: Information Security & Risk Management

profileKrishRisk1_Sol
FinalProjectTask2-ProjectAssessmentPlantemplate.docx

Running Head: INFORMATION SECURITY AND RISK MANAGEMENT 9

ISOL 533 - Information Security and Risk Management

Student’s Name:

Professor’s Name:

Date:

EXECUTIVE SUMMARY

The Health Network Hospital has its headquarters located in Minneapolis, Minnesota with 600 employees and generates an average of $500 million annually. Furthermore, it has its branches in Portland, Oregon, and Arlington, Virginia which support combinations of collective operations with each carrying out production systems managed by respective third-party data center hosting buyers in the strategic locations near a co-location data center.

The company comprises of three major products, that is, the net exchange which securely handles electronic media message from large hospital customers and routes them to the receiving customers like clinics. HNetPay, on the other hand, is a web portal that deals with the management of safe payments and billing. HNetConnect is an online directory listing medical staffs and facilities enabling customers to choose the service of their choice as even doctors credentials are updated frequently in their respective profiles

The institution operates in 3 production data centers providing high availability across its products which host an average of 1,000 production servers, with 650 laptops as well as mobile devices issued to employees.

The Information Technology in the Health Network Inc. provides information security with the following objectives;

i) Information is made accessible to only the authorized users whether externally or internally

ii) Protection of the information, as a way of maintaining credibility and integrity to the Health Network users.

iii) Ensuring training of personnel pertaining to information security

iv) Ensuring that breach of information and any suspected weaknesses are reported on time.

RISKS- THREATS- WEKNESSES WITHIN EACH DOMAIN

R-T-W

Domain Impacted

Risk Impact / Factor

Risk : A user destroying data and deletes files in an organization

Threat : A user downloading unknown attachment from email

Weakness : A user failing to lock the company's computer with weak password

User Domain

3

Risk : A user computer or devices which provide access to computer resources

Threat : Stealing of assets owned by company like laptops and mobile devices

Weakness : insufficient Security on Company’s Equipment

Workstation Domain

1

Risk: loss of Customers

Threat : production outages due to unforeseen circumstances like natural calamities.

Weakness : possible weakness involves generation of alerts.

LAN Domain

2

Risk: configuration errors of routers and firewall

Threat : viruses and communication outages well as DDoS Attacks

Weakness : lack of Backup data due to a failure of following procedures.

WAN-TO- LAN DOMAIN

2

Risk: loss of Customers

Threat : production outages due to unforeseen circumstances like natural calamities.

Weakness : lack of Backup data due to a failure of following procedures.

WAN Domain

2

Risk : Unpermitted access of company’s information public Internet

Threat : Internal threats

Weakness : lack of proper control being put in place and failure to monitor Networks.

Remote Access Domain

2

Risk : Destruction of primary data center by fire

Threat : Changes in regulatory landscape that may impact operations

Weakness : insufficient processes to content changes made on regulations

System Application Domain

2

Risk : Unauthorized access from Internet to corporate servers and applications Threat : Internal Threats Weakness : Failure to monitor networks

Remote Access Domain

1

Risk : User destroys data in the application and deletes all files she has access too. Threat : : Changes in regulatory landscape that may impact operations Weakness : Lack of proper backups in the organization

Application Domain

Risk : Technician (user) uses P2P file sharing on company-owned PC Threat : Employee blackmail Weakness : inserting infected USB or Flash Drive

User Domain

2

Risk : Hacker penetrates your IT infrastructure Threat : gains access to your internal network because default Weakness : A firewall with unnecessary ports

LAN- WAN Domain

1

Risk : Workstation OS has known vulnerabilities Threat : Software Vulnerabilities Weakness : A workstation Hard drive fails

Workstation Domain

2

Risk : The Telecommunications closet where the switches and routers reside is unlocked and open because the AC is broken. Threat : Unauthorized access in LAN workstations Weakness : LAN OS server known to have software vulnerability

LAN Domain

2

Risk : A server can receive DDoS or DoS attacks from internet Threat : A network outage Weakness : FTP server can allow illegal upload of software

WAN Domain

1

Risk : A database Server attacked by SQL injection Threat : Crippling an organization Email Server Weakness : Corporate Data server has no backups

Application Domain

3

Risk : A general-purpose sniffer is found on organization-controlled client PCs Threat : Loss of data Weakness : Failure of workstation Domain

Workstation Domain

2

Table 1

Health Network Inc. Laws and regulations include;

i) Offering quality standards to their patients

ii) Offering Internet-related products and services through IT-enabled systems,

References

Righthand, S., Kerr, B. B., & Drach, K. (2013). Child Maltreatment Risk Assessments: An Evaluation Guide. Hoboken: Taylor and Francis.

Rushton, R. (2006). What a week to risk it all. London: Piccadilly Press.

Tasler, Nick, Schirner, & Buck. (2015). The Impulse Factor: Why Some of Us Play It Safe and Others Risk It All. Brilliance Audio.