revise this too, see attachment

profileArun1990
P1_Executive-Summary.pdf

Project 1 - Information Systems and Identity Management

Executive Summary

Donnell Clark

CST 610 3131 Cyberspace and Cybersecurity Foundations (2178)

University of Maryland University College

November 12, 2017

Student

With the dictates from HIPAA Security Rule, our organization obliged and developed

strong encryption strategy aimed at emphasizing on security concern, developed through the

Corporate Integrity Agreements (CIA) (cited in Brown, 2005), program to enhance a substantial

and reliable integrity, confidentiality and availability of patients’ information. The organization

utilizes the two password cracking products, Cain and Abel, and Ophcrack capable of

acknowledging various aspects within securing concerns in our networks, strengthening our

physical and logical security, and mitigating every risk that can be of extreme significance in this

technology-oriented world.

If the leadership takes no initiative in curbing the risk, then the facility will have to pay

the price for that. First, a lot of information will be exposed to a lot of unauthorized people,

hackers. They will spread a negative image about the facility hence destroying the hospital`s

reputation. This could reduce the number of clients our facility has and put a lot of trust in it.

There is a risk of losing money once the finance department is hacked. With the aid of

technology, losing information and money to hackers is so easy, and thus it has to be protected at

all costs. Otherwise, it will render the facility bankrupt and bad reputation. Compromising the

patient system is quite easy, and this could also lead to the administration of wrong prescription

to the wrong patient. It is the worst thing ever to happen in such a medical facility as this.

The risk managers could easily transfer the risk from the system. Risk transfer could be

achieved in the form of taking a backup and keeping it safe if a breach happens. A backup could

easily replace the lost data in an immediate effect. Again, it is advisable that the hospital to take

an insurance cover of the vital and sensitive gadgets that are quite expensive to procure in case of

any information breach.

At the same time, the top management could mitigate the problem in quite various ways.

As urged by Sharma and Liu (2013) and also affirmed by Daunton et al, (2012), that Prevention

is better than Cure. The management should, therefore, work towards preventing such risks from

happening at all. These risks could be avoided through the following ways:

• To minimize the cases of unauthorized entry and hacking, the facility will have to

use Virtual Private Network as an intermediary when one is surfing.

• Firewalls can also be installed on the system. It will help in reducing the chances

of unauthorized access from an unknown end.

• Each user should have a profile which will require a username and a password

before being granted access to the server. The system should be able to log a user

if they are not near the personal computer for a maximum of five minutes

According to Chaudhry et al, (2010), the prevention measures of any information system

tends to be quite expensive. The system needs an antivirus that could detect any breach,

synchronize the whole system and shut down any unauthorized access once detected. To have it

in place means that the hospital will have to incur a lot. Otherwise, the facility will incur almost

double the amount once the information is leaked to the public.

I also recommended that the password cracking products be installed on the users’ PC

with their consent and under an administrative role in the system. The installation consent

emanates from the fact that the software does not perform any data accessing or performing any

other tasks sternly without the users’ knowledge.

Our facility usually has various datasets that manage confidential: financial data,

employees files, patients’ health information. I would, therefore, recommend that every dataset

should be regarded corporate assets and, thus, users should acknowledge that their disclosure or

manipulation might result in a severe financial drawback. The physicians and other support staff

should, therefore, ensure that health data are qualitatively distinct from proprietary corporate

data.

References

Brown, M. T. (2005). Corporate Integrity: Rethinking Organizational Ethics and Leadership.

Cambridge University Press.

Chaudhry, B., Wang, J., Wu, S., Maglione, M., Mojica, W., Roth, E. ... & Shekelle, P. G. (2006).

Systematic Review: Impact of Health Information Technology on Quality,

Efficiency, and Costs of Medical Care. Annals of Internal Medicine, 144(10), 742-752.

Daunton, A., Puig, S., Taniere, P., Forde, C., Alderson, D., & Tucker, O. N. (2012). Prevention

Is Better Than Cure. Journal of Surgical Case Reports, 2012(6), 14-14.

Sharma, N., & Liu, M. (2013). Prevention Is Better Than Cure. Medical Teacher, 35(4), 339-339.