CSIS 343 – Cyber security
Week 2
10th October
Assignment 2: Cybersecurity Risk Assessment and Management Plan
Due Week 2 and worth 75 points
Imagine you are a cybersecurity risk analyst for a mid-sized healthcare organization that handles sensitive
patient data. Your task is to conduct a comprehensive cybersecurity risk assessment and develop a risk
management plan to protect the organization's data from cyber threats. Write a three to five-page paper in
which you:
1. Introduction to Risk Assessment: Provide an overview of the importance of cybersecurity risk
assessment and its role in protecting sensitive healthcare data.
2. Risk Identification: Identify potential cybersecurity risks that the healthcare organization may
face, considering the sensitivity of patient data and regulatory requirements (e.g., HIPAA).
3. Risk Assessment: Assess the likelihood and potential impact of each identified risk using a risk
matrix or similar methodology. Prioritize the risks based on their severity and potential
consequences.
4. Vulnerability Analysis: Analyze vulnerabilities within the organization's IT systems and
processes that contribute to the identified risks. Explain how these vulnerabilities can be
exploited.
5. Threat Analysis: Identify potential threats and threat actors that could target the organization's IT
systems and patient data. Consider both external and internal threats, including cyberattacks and
insider threats.
6. Risk Mitigation Plan: Develop a comprehensive risk mitigation plan that includes specific
measures to reduce or eliminate the identified risks. Explain the rationale behind each mitigation
measure and how it aligns with the organization's goals.
7. Resource Allocation: Allocate resources (budget, personnel, technology) for implementing the
risk mitigation plan. Discuss the cost-benefit analysis of each resource allocation decision.
8. Monitoring and Reporting: Describe how the organization will monitor the effectiveness of the
risk mitigation measures and report on progress to the executive team, regulatory authorities, and
internal stakeholders.
9. Documentation and Compliance: Explain the importance of documenting the risk assessment
process and ensuring compliance with relevant healthcare regulations (e.g., HIPAA) and
cybersecurity standards.
10. Continuous Improvement: Outline strategies for continuously improving the organization's
cybersecurity risk management practices based on feedback, changes in the threat landscape, and
industry best practices.
Your assignment must follow these formatting requirements:
Be typed, double spaced, using Times New Roman font (size 12), with one-inch margins on all
sides; citations and references must follow APA or school-specific format. Check with your
professor for any additional instructions.
Include a cover page containing the title of the assignment, the student’s name, the professor’s
name, the course title, and the date. The cover page and the reference page are not included in
the required assignment page length.
The specific course learning outcomes associated with this assignment are:
Compare and contrast the methods of disaster recovery and business continuity.
Explain risk management in the context of information security.
Use technology and information resources to research issues in disaster recovery.
Write clearly and concisely about disaster recovery topics using proper writing mechanics and
technical style conventions.
Grading for this assignment will be based on answer quality, logic / organization of the paper, and
language and writing skills, using the following rubric.
Points: 50 Assignment 2: Cybersecurity Risk Assessment and Management Plan
Criteria Unacceptable
Below 60% F
Meets Minimum
Expectations
60-69% D
Fair
70-79% C
Proficient
80-89% B
Exemplar
90-100%
1. Analyze
proper physical
access control
safeguards and
provide sound
recommendatio
ns to be
employed in the
registrar's
office.
Weight: 21%
Did not submit or
incompletely analyzed
proper physical access
control safeguards and
did not submit or
incompletely provided
sound recommendations
to be employed in the
registrar's office.
Insufficiently
analyzed proper
physical access
control safeguards
and insufficiently
provided sound
recommendations
to be employed in
the registrar's
office.
Partially;analyz
ed proper
physical access
control
safeguards and
partially;provid
ed sound
recommendatio
ns to be
employed in the
registrar's
office.
Satisfactorily
analyzed proper
physical access
control safeguards
and satisfactorily
provided sound
recommendations
to be employed in
the registrar's
office.
Thoroughly
analyzed prop
physical acce
control safeg
and thorough