Project Part 2- Info Security & Risk Mgmt (ISOL-533)
Running head: Project paRT 1 1
Project paRT 1 8
Project Part 1
Risk Assessment for Health Network Inc.
Below Risk Assessment for Health Network Inc includes the assessment by each threat identified/being identified. For each threat, the scope of the risk assessment is addressed involving the assets of the company that are affected, stakeholders involved with the threat, the business processes the threat is posing towards, and the tools and technological equipment that is being used to conduct and built this risk assessment plan are addressed thoroughly. The following are the Threats posed to the company as of the current situation and considering the background of the company and the Risk Assessment is discussed below each threat.
DDOS Attack: The security risk posed by and DDOS attack on Health network Inc's website is medium among other threats. The Website for Health Network Inc could be focused on and penetrated/bombarded with overabundance traffic bringing about a downtime because of the maintenance or work done for doing this bombard testing to access the website. This can cost the company around $700 every hour. The security threat/risk was evaluated utilizing Hing3, a parcel/packets creating technology. The instrument was utilized to successfully barrage the website with traffic in a "Penetration Test" which brought about absence of admittance to the website for about thirty minutes. The attack can be forestalled and dealt with by having a response plan in place which clearly identifies how we can respond to this threat, making sure about the organization infrastructure, and fundamental security for the organization, for example: setting up firewalls etc. (Dobran, 2018).
Insider threat: Anything that is intentional and done by an insider that is security risk to the company is a deadly combination. The security hazard is high no matter how much impact it has on the company at that moment. Breach of trust is very serious threat to any organization. Employee authorization interface is kept in place for gaining access to the server infrastructure and a USB stick was effectively positioned ‘on the server’. Malware can adequately incapacitate the workers or take information prompting misfortunes of roughly at anywhere starting from $2000. Insider threat can be forestalled by having physical security and proficient access controls by utilizing passwords and verification (authorization processes).
Theft: The security hazard is high. An external party acting like a representative had the option to access the worker rooms and take CD drives and a PC that had been left running in the room. The answer for theft is setting up solid physical security for section and exit from the premises. The association should likewise set up powerful access controls and personality access the executives to guarantee that insiders are responsible if hardware gets taken.
Loss of Company Devices/Equipment: The security risk posed is High. One of the organization telephones was admittance and touchy data had the option to be recovered including client information and the product utilized by the organization. The loss of gadgets and information can cost the organization up to $10,000. The danger is high since it can open up better approaches for attacking the association, for example, the most recently popular form of threat "Identity Theft". Passwords ought to consistently be utilized on telephones and workstations. The telephones and PCs ought to be arranged to eradicate all information after erroneous secret phrase endeavors and can be bolted in the wake of getting lost to forestall unlawful access. (Hein, 2019).
Unstable/Insecure Software: The danger is medium. A study was done on a couple of clients of the organization's previously dealt with/addressed insecure software. The clients felt demotivated with the mistakes in programming halfway their services and were bound to utilize different associations as opposed to Health Network Inc. The business sway is probably going to cost clients and misfortunes of up to $5000 in lost benefits. The current and forthcoming organizations of programming ought to be examined and the issues settled
Cloud Computing Security: The danger is medium. The information being moved to outsider merchants might be breached without company's knowledge. Programmers may focus on the data on the cloud or in any case the cloud supplier may decrease their security or inside controls. There are lawful liabilities that may result because of absence of security of patient information in the cloud just like the prerequisite by HIPAA. This may cost the business up to $100,000 in lost data and lawful liabilities. This might be illuminated by knowing the usefulness of the cloud supplier including the assurance given to the information. The information can likewise be subjected to encryption or through a better transaction service like EDI Transactions before it is sent to the cloud.
Advanced Persistent Threats: The security risk is medium for this kind of threat. Since the Company's website can be accessible on the web, it could fall subject to advanced persistent threats by enemy countries, hacktivists, and different individual groupings. Protected innovation can be taken and delicate information while subverting the foundation of the framework. This will probably cost the organization up to $30,000 in harms, ransomware, or risk. This danger can be forestalled by playing out a threat investigation and presenting controls in an ideal opportunity for alleviation of the weaknesses that have been distinguished.
Social Media: The security risk is medium for the organization. Social media can harm the status and trust of the company through negative exposure. Legitimate risk may emerge because of negative comments on different organizations like google reviews etc. There are security issues identified with the utilization of social media, for example, spy-product, hacking, and bugs. Social media can burn through worker time and may likewise bring about representative making notoriety issues for the organization by giving incorrectly comments on social media. The effect is loss of notoriety and may prompt misfortunes in harmed notoriety, lawful obligation, and malware attacks which may cost the organization up to $50,000 or more. Endorsement to social media ought to be restricted to a couple of individuals who deal with the social media accounts in the interest of the organization. The IT division ought to be incorporated to set up appropriate social media arrangements and security intercessions to guarantee that clients are sheltered on the web and that no malware can be downloaded from the social media locales during ordinary movement. The social media pages ought to likewise be firmly observed for what content the representatives are getting to or posting about. (Steve, 2014).
Natural Disasters: The security risk for this one is low. Floods, fires, typhoons, Cyclones, Tornado’s and tremors may influence the activity of the business and cause harm to property. The business effect of such a catastrophe is high because of the subsequent annihilation and loss of revenue because of downtime and fix of harmed property. The answer for this issue is getting ready for the calamity. This can be through counteraction by introducing fire quenchers. An exit/evacuation plan ought to be set up in the event that there is having to clear individuals during or before a debacle. Information ought to be secured by having an offsite reinforcement. Protection against such disasters may assist with easing the fix costs after the episode. Emergency courses of action could be set up to empower progression by utilizing the Portland, Arlington, or Minneapolis branches if one of them is influenced.
Social Engineering: The security risk posed to the company by this one is high. Phishing was utilized to acquire sign in qualifications to the framework from the senior administrative staff. A USB stick was left on the work area of one of the representatives and they connected it to their work spot to perceive what was in it. Such social engineering can be utilized by attackers to present malware, take qualifications, or cash from the organization. This can cost the organization a great deal of cash because of misrepresentation as well as legitimate liabilities. The answer for this danger is to instruct the workers on the threats of social engineering including their own messages and gadgets. Legitimate arrangements ought to likewise be executed to forestall sharing of delicate data that can without much of a stretch be focused by the attackers. (Winder, 2018).
Network Vulnerabilities: The security risk posed to the company by this one is high. Nmap was utilized to examine the associations network for open ports that could be utilized to execute an attack. The association's PCs were utilized to download an email connection. Absence of checking devices for approaching and active information can result in download of malware or sending of delicate organization information to outside areas. The effect of such network imperfections can extend from downtime to taking of delicate business information that can bring about lawful liabilities and will cost the organization at any rate $10,000. The answer for this issue is performing successive entrance tests to distinguish and close open ports that might be utilized by attackers. Software ought to be put on organization gadgets to recognize any touchy active data that may not be approved by the organization. Downloaded data ought to likewise be checked by a firewall to guarantee that solitary safe information is permitted to pass and be accessed by the organization approved servers. (Wang, and Yang, 2017).
Unauthorized Software Installation: The security risk posed to the company by this one is low. The organization workstations were utilized to introduce an open source application from the web and required the organization n authorization before the software could be run. The security might be enough to keep most workers from introducing unauthorized software. Notwithstanding, this may happen bringing about legitimate liabilities for the organization. This will cost the organization at least $2000. The installation of unauthorized software can be forestalled by decreasing overseer benefits, authorizing strategies, and ensuring the representatives know about these approaches. (Posey, B. 2014).
References
Dobran, B. (2018, September 10). 7 demonstrated strategies to forestall DDoS assaults: Make a security plan today! Retrieved from https://phoenixnap.com/blog/forestall ddos-assaults
Gibson, D. (2015). Lab #5 Identifying Risks, Threats, and Vulnerabilities in an IT Infrastructure Using Zenmap® GUI (Nmap) and Nessus® Reports. In Managing risk in information systems. Burlington, MA: Jones & Bartlett Learning.
Hein, D. (2019, September 12). Instructions to make sure about your organization when a cell phone is lost or stolen. Retrieved from https://solutionsreview.com/cell phone the executives/how-to-make sure about your-organization when-a-cell phone is-lost-or-taken/
8 different ways to lessen unapproved programming - GCN. (2014, November 17). Retrieved from https://gcn.com/articles/2014/11/17/8-steps-lessening unapproved software.aspx
Steve, A. (2014, October 23). Top five dangers organizations face when utilizing social media. Retrieved from https://techxb.com/top-five-hazards organizations face-when-utilizing web-based media/
Wang, Y., and Yang, J. (2017, March). Moral hacking and organization protection: Choose your best network weakness filtering apparatus.
Winder, D. (2018, May 23). Social building: The greatest security danger to your business. Retrieved from https://www.itpro.co.uk/social-designing/30017/social-building the-greatest security-hazard to-your-business