Research Paper for information security and Risk management

profilepcheedella
ISOL533InformationSecurityandRiskManagementResidencyProject.docx

Residency Make Up Session Assignment

Course

ISOL 533—Information Security and Risk Management

Deliverable

Prepare a report to address all aspects of the case assignment. This report should be no less than 10 pages of content. You need to include outside sources and properly cite and reference your sources. You must have at least 10 references, 5 of which must be scholarly peer-reviewed articles. In addition to the 10 pages of content, you will want a title page and a reference sheet. This report needs to be in proper APA format.

Paper Sections

The following sections should be outlined as Headers in the paper.

Introduction, thesis statement, overview, purpose Background, discuss history of topic Discussion, identify benefits, obstacles, innovations Conclusion, summarize the overall study, lessons learned References, minimum three references with citations in the body

 

All written reports should be submitted in MS Word. The paper submission will use SafeAssign. Please ensure to use the proper Author, YYYY APA citations with any outside content brought into the paper.

Be prepared to present a 10-minute presentation on this assignment.

Students must submit both written assignment and presentation slides in the folder labeled “Make Up Assignment” in your iLearn course.

Assignment

Below are Residency Project examples by Faculty.

Residency Project Option 1

The majority of the paper MUST address the highlighted topic(s) below as it relates to Information Security Risk Management. Specific case studies, hardware, software, service or systems may be used as short examples but should only represent a small portion of the total paper.

Select one or more of the following topics

1. How Analytics is used in Information Security Risk Management

2. Information Security Risk Management in the IT Data Centers

Using either or both of the topics above, write a research paper which includes between 5 and 10 References/Cited-Works (a majority dated 2015 or newer ) of which 2 must be Peer-Reviewed . Highlight the Peer-Reviewed works (in Yellow) on the Reference/Works-Cited last page.

Once the paper is completed, add an Overview to the Introduction of the paper. The Overview must contain at least one Hypothesis and a Synopsis of what is contained in the paper. For this paper, a Hypothesis is a statement you believe to be true based on the research you conducted. As an example: “Small businesses are less likely to conduct a thorough risk assessment”.

The quality and thoroughness of the paper, as defined in the rubric, will determine the grade assigned. Papers containing the minimum number of references and/or minimum number of pages will most likely not earn a high grade.

Residency Project Option 2

Incident Response Paper

Using NIST’s SP 800-61 “Computer Security Incident Handling Guide”, develop an Incident Response Plan (IRP) that will address one or more of your security risks that you identified in your Risk Assessment. Google and find other actual IRPs on the Internet and review to see what type of information is included. At a minimum, your plan should include the following sections:

· Roles: who will respond to the incident and notification/escalation procedures? Who is responsible for writing the IRP?

· Training: specify a training frequency

· Plan testing: How (and how often) will you test the plan?

· Incidents: What defines an “incident”? Define some security incidents that you may encounter on your network.

· Incident Notification: What happens when an incident is detected?

· Reporting/tracking: How will you report and track incidents? What about capturing “lessons learned”?

· Procedures: Select one of your security risks identified in your Risk Assessment. Prepare procedures for addressing the incident in the event that the incident actually happens. In this section, address the following subsections specific to your risk that you are identifying.

· Preparation

· Detection and Analysis

· Containment

· Eradication

· Recovery and Post-Incident Activity

Note: there are several scenarios in the appendix of the NIST document. You can use, for instance, Scenario 11: Unknown Wireless Access Point to help develop the response procedures for wireless access, as an example. Use any of these to help flesh out your procedures but the procedure you agreed to use must be one that addresses a risk you identified in your Risk Assessment.

Grading Criteria

Criteria

Document is at least 10 double-spaced pages. Paper is well-written with minimal typing, spelling, or grammatical errors. 10%

Required sections (above) are appropriately addressed. 25 points (5 each), 50 points for the Procedures Section. 75%

Procedures provide sufficient information to enable recovery and mission restoration. 15%