revise this too, see attachment
Project 1 - Information Systems and Identity Management
Executive Summary
Donnell Clark
CST 610 3131 Cyberspace and Cybersecurity Foundations (2178)
University of Maryland University College
November 12, 2017
Student
With the dictates from HIPAA Security Rule, our organization obliged and developed
strong encryption strategy aimed at emphasizing on security concern, developed through the
Corporate Integrity Agreements (CIA) (cited in Brown, 2005), program to enhance a substantial
and reliable integrity, confidentiality and availability of patients’ information. The organization
utilizes the two password cracking products, Cain and Abel, and Ophcrack capable of
acknowledging various aspects within securing concerns in our networks, strengthening our
physical and logical security, and mitigating every risk that can be of extreme significance in this
technology-oriented world.
If the leadership takes no initiative in curbing the risk, then the facility will have to pay
the price for that. First, a lot of information will be exposed to a lot of unauthorized people,
hackers. They will spread a negative image about the facility hence destroying the hospital`s
reputation. This could reduce the number of clients our facility has and put a lot of trust in it.
There is a risk of losing money once the finance department is hacked. With the aid of
technology, losing information and money to hackers is so easy, and thus it has to be protected at
all costs. Otherwise, it will render the facility bankrupt and bad reputation. Compromising the
patient system is quite easy, and this could also lead to the administration of wrong prescription
to the wrong patient. It is the worst thing ever to happen in such a medical facility as this.
The risk managers could easily transfer the risk from the system. Risk transfer could be
achieved in the form of taking a backup and keeping it safe if a breach happens. A backup could
easily replace the lost data in an immediate effect. Again, it is advisable that the hospital to take
an insurance cover of the vital and sensitive gadgets that are quite expensive to procure in case of
any information breach.
At the same time, the top management could mitigate the problem in quite various ways.
As urged by Sharma and Liu (2013) and also affirmed by Daunton et al, (2012), that Prevention
is better than Cure. The management should, therefore, work towards preventing such risks from
happening at all. These risks could be avoided through the following ways:
• To minimize the cases of unauthorized entry and hacking, the facility will have to
use Virtual Private Network as an intermediary when one is surfing.
• Firewalls can also be installed on the system. It will help in reducing the chances
of unauthorized access from an unknown end.
• Each user should have a profile which will require a username and a password
before being granted access to the server. The system should be able to log a user
if they are not near the personal computer for a maximum of five minutes
According to Chaudhry et al, (2010), the prevention measures of any information system
tends to be quite expensive. The system needs an antivirus that could detect any breach,
synchronize the whole system and shut down any unauthorized access once detected. To have it
in place means that the hospital will have to incur a lot. Otherwise, the facility will incur almost
double the amount once the information is leaked to the public.
I also recommended that the password cracking products be installed on the users’ PC
with their consent and under an administrative role in the system. The installation consent
emanates from the fact that the software does not perform any data accessing or performing any
other tasks sternly without the users’ knowledge.
Our facility usually has various datasets that manage confidential: financial data,
employees files, patients’ health information. I would, therefore, recommend that every dataset
should be regarded corporate assets and, thus, users should acknowledge that their disclosure or
manipulation might result in a severe financial drawback. The physicians and other support staff
should, therefore, ensure that health data are qualitatively distinct from proprietary corporate
data.
References
Brown, M. T. (2005). Corporate Integrity: Rethinking Organizational Ethics and Leadership.
Cambridge University Press.
Chaudhry, B., Wang, J., Wu, S., Maglione, M., Mojica, W., Roth, E. ... & Shekelle, P. G. (2006).
Systematic Review: Impact of Health Information Technology on Quality,
Efficiency, and Costs of Medical Care. Annals of Internal Medicine, 144(10), 742-752.
Daunton, A., Puig, S., Taniere, P., Forde, C., Alderson, D., & Tucker, O. N. (2012). Prevention
Is Better Than Cure. Journal of Surgical Case Reports, 2012(6), 14-14.
Sharma, N., & Liu, M. (2013). Prevention Is Better Than Cure. Medical Teacher, 35(4), 339-339.