CSIS 343 – Cyber security
Week 2
3rd October
Assignment Cyber security Risk Management Plan:
Due Week 2 and worth 75 points
In this task, you will create a Cybersecurity Risk Management Plan for a medium-sized technology
company. The goal is to establish a structured approach to identifying, assessing, and mitigating
cybersecurity risks. Follow these steps:
1. Scope Definition: Define the scope of the Cybersecurity Risk Management Plan. Specify which
systems, networks, and data assets are within the scope of the plan. Identify key stakeholders and
departments involved in risk management.
2. Risk Assessment Framework: Establish a risk assessment framework that outlines the
methodology, tools, and criteria for assessing cybersecurity risks. Choose a risk assessment
model (e.g., NIST Cybersecurity Framework) and adapt it to your organization's needs.
3. Threat Identification: Identify potential cybersecurity threats that the organization may face.
Consider both internal and external threats, such as malware, insider threats, social engineering,
and supply chain risks.
4. Vulnerability Assessment: Conduct a vulnerability assessment to identify weaknesses in the
organization's IT infrastructure, software, and configurations. Include factors such as outdated
software, misconfigured devices, and weak access controls.
5. Risk Analysis: Assess the likelihood and potential impact of each identified threat and
vulnerability. Use the risk assessment model to calculate risk scores and prioritize risks based on
their severity.
6. Risk Mitigation Strategies: Recommend specific risk mitigation strategies for high-priority risks.
This may include technical controls, policies, procedures, and employee training. Explain the
rationale behind each mitigation measure.
Your assignment must follow these formatting requirements:
Be typed, double spaced, using Times New Roman font (size 12), with one-inch margins on all
sides; citations and references must follow APA or school-specific format. Check with your
professor for any additional instructions.
Include a cover page containing the title of the assignment, the student’s name, the professor’s
name, the course title, and the date. The cover page and the reference page are not included in
the required assignment page length.
The specific course learning outcomes associated with this assignment are:
Compare and contrast the methods of disaster recovery and business continuity.
Explain risk management in the context of information security.
Use technology and information resources to research issues in disaster recovery.
Write clearly and concisely about disaster recovery topics using proper writing mechanics and
technical style conventions.
Grading for this assignment will be based on answer quality, logic / organization of the paper, and
language and writing skills, using the following rubric.
Points: 75 Cyber security Risk Management Plan
Criteria Unacceptable
Below 60% F
Meets
Minimum
Expectations
60-69% D
Fair
70-79% C
Proficient
80-89% B
Exemplary
90-100% A
1. Explain the basic
primary tasks, ongoing
evaluations, and major
policy and procedural
changes that would be
needed to perform as
the BC lead / manager.
Weight: 20%
Did not submit or
incompletely
explained the
basic primary
tasks, ongoing
evaluations, and
major policy and
procedural
changes that
would be needed
to perform as the
BC lead /
manager.
Insufficiently
explained the
basic primary
tasks, ongoing
evaluations,
and major
policy and
procedural
changes that
would be
needed to
perform as the
BC lead /
manager.
Partially
explained the
basic primary
tasks, ongoing
evaluations,
and major
policy and
procedural
changes that
would be
needed to
perform as the
BC lead /
manager.
Satisfactorily
explained the
basic primary
tasks, ongoing
evaluations,
and major
policy and
procedural
changes that
would be
needed to
perform as the
BC lead /
manager.
Thoroughly
explained the
basic primary
tasks, ongoing
evaluations,
and major
policy and
procedural
changes that
would be
needed to
perform as the
BC lead /
manager.
2. Provide insight on
how to plan the
presentation to garner
management and
Board buy-in for those
who are skeptical.