Week 3 remaining

profileee2939
Week3-SystemAssuranceSecurity.zip

Week 3/cf_Course_Security_Secenario (2).docx

CU_Horiz_RGB IT4803 – Systems Assurance Security

CU_Horiz_RGB

Course Security Scenario

Course assignments require you to address security assurance issues. Use the information in scenario below to complete your course security policy planning assignments. The scenario is relatively simple, so make sure to state any assumptions that you make to fill in gaps when necessary for substantiating positions taken in your assignment work.

Background

You have been hired as an information assurance and compliance consultant at a large health system called Laskondo Healthcare. The organization is comprised of three (3) hospitals, 1,000 licensed beds, 8,000 employees, of which 1,750 are medical staff, and over 2,000 volunteers.

As a healthcare system, Laskondo manages and transmits a considerable amount of confidential data, including protected health information (PHI) on behalf of its patients. This data is often transmitted between and with external healthcare professionals and offices, as well as suppliers and vendors, as needed. Additionally, data is often shared within the three system hospitals.

Upon starting the job, you quickly understand that information security and compliance have not been properly implemented or governed.

Laskondo is lacking organization-wide standardized policies and strategic plans that adequately address system security assurance. In a recent audit, there were findings that the security controls in place at all three hospital facilities were lacking from a HIPAA-compliant perspective. Additionally, proper business continuity efforts have yet to be developed, implemented or tested, leaving the organization with unwanted risk of major disruption or incident.

The CIO has recognized that there are systemic policy weaknesses and has asked you to draft new organizational system assurance security policies that adequately guide the organization in the areas listed below using modern systems assurance security policies, practices and techniques.

Policy Areas:

· Acceptable Use.

· Workstation Security.

· Password Management.

· Logging Standards. 

· Vulnerability Management.

· Patch Management.

· Logical Access Control.

· Physical Access Control.

· Separation of Duties.

· Change Control Management.

· Monitoring.

· Access Request Approvals.

· Business Continuity Planning.

· Incident Response Procedures.

· Encryption Usage in a regulated healthcare environment.

· Remote Access.

· Network Device Security.

· Intrusion Detection.

· Application Security and Testing.

Technical Details

The high-level technical infrastructure details of the organization are as follows:

· Networking devices

· Firewalls (1 in each hospital)

· Routers / Switches (multiple in each hospital)

· Servers

· Baremetal – VMware ESX 5.5 (5). Comment by csprafka: Tim, I hope these tools are covered in the labs. That would be idea. If they are not, we’ll need to give learners resources on these topics if they are not covered in the Labs.

· Baremetal - CentOS 7.3 (Qty 15).

· Baremetal – Windows Server 2012 R2 (Qty 35).

· Virtual – CentOS Linux (Qty 50).

· Virtual – Windows Server 2012 R2 (Qty 125).

· Workstations

· Windows 10 desktop systems, various models (Qty 250).

1

2

Week 3/Week 3 ddisc n assigment.docx

Week 3 – Discussion 1

u03d1] Unit 3 Discussion 1

Layered Defenses

Suppose you were tasked with creating a layered security approach for a remote workforce in a healthcare organization. Consider the three (3) most important layered controls you would consider implementing for this workforce, and indicate why you believe those controls to be the most important. [u03a1] Unit 3 Assignment 1

Week 3 – Assignment 1

Eliminating Threats with a Layered Security Approach

Overview

There are many key concepts of information assurance and security, but one important fact to note is that eventually, over time, a single security control will eventually fail. This is what makes layered security defenses a very important part of this concept, so that when a single control does indeed fail, there are other controls in place that will together help mitigate the risk of the failed control.

In this assignment you will complete the Eliminating Threats With a Layered Security Approach lab and write policies for Password Management and Logging Standards.

Preparation

Do the following using items found in the Resources:

· Download the Assignment X Template. You will use this Word template for your assignment submission.

· Open Eliminating Threats with a Layered Security Approach, found in this unit, and read the introduction.

· Review the Course Security Scenario document found in the Resources for context when writing your security policies in Part 2.

Instructions

Part 1 - Security Planning: Password Management and Logging Standards Presentation

Consider the following policies using information found in the Course Security Scenario as context.

1. Password Management.

2. Logging Standards.

Create a 10–15 minute presentation (using a common presentation software of your choice) that describes Password Management and Logging Standards policies that you would recommend to stakeholders interested in organizational security for the company described in the Course Security Scenario. Your presentation must include audio narration with supporting visual depictions.

Consider the following scoring guide criteria as you complete your assignment:

. Create a password management policy that is appropriate for the Course Security Scenario.

. Create a logging standards policy that is appropriate for the Course Security Scenario.

. Interpret the importance of disabling unneeded services and the potential detriment if this is not done.

. Create a presentation that accurately communicates a security plan to stakeholders.

Additional Instructions

Place your well-labeled written work from parts 1 and 2 in the Assignment X Template and submit it.

Submit part 3 in a separate file. If the file exceeds 15 Mb, please zip the file.

.