NAME
Strayer University
CIS 349 – Information Technology Audit and Control
Risk Assessment and Mitigation Strategies
Risk Assessment and Mitigation Strategies
Create a hypothetical organization specializing in e-commerce, with multiple global locations.
Describe the organization's primary business functions, the technology infrastructure supporting
these functions, and potential threats such as cyber-attacks, natural disasters, and supply chain
disruptions.
Write a 10-15 page paper that begins with a comprehensive risk assessment for the organization,
identifying the most critical risks and vulnerabilities.
●Develop a contingency plan that includes Business Impact Analysis (BIA), Incident
Response Plan (IRP), Disaster Recovery Plan (DRP), and Business Continuity Plan
(BCP).
●Detail specific policies and procedures necessary to address each component of the
contingency plan.
●Discuss the implementation processes and strategies to ensure the organization is
prepared for various scenarios.
●Create a hypothetical cyberattack scenario and explain how the contingency plan is
equipped to handle it, including incident response and recovery timelines.
●Explore ethical concerns related to customer data privacy in the context of incident
response and recovery.
Your assignment must follow these formatting requirements:
●Be typed, double spaced, using Times New Roman font (size 12), with one-inch margins
on all sides; citations and references must follow APA or school-specific format. Check
with your professor for any additional instructions.
●Include a cover page containing the title of the assignment, the student’s name, the
professor’s name, the course title, and the date. The cover page and the reference page are
not included in the required assignment page length.
The specific course learning outcomes associated with this assignment are:
●Explain risk management in the context of information security.
●Develop a disaster recovery plan for an organization.
●Summarize the various types of disasters, response and recovery methods.
●Compare and contrast the methods of disaster recovery and business continuity.
●Explain and develop a business continuity plan to address unforeseen incidents.
●Describe crisis management guidelines and procedures.
●Describe detection and decision-making capabilities in incident response.
●Develop techniques for different disaster scenarios.
●Evaluate the ethical concerns inherent in disaster recovery scenarios.
●Use technology and information resources to research issues in disaster recovery.
●Write clearly and concisely about disaster recovery topics using proper writing
mechanics and technical style conventions.
Grading for this assignment will be based on answer quality, logic / organization of the paper,
and language and writing skills, using the following rubric.
Points: 200 Risk Assessment and Mitigation Strategies
Criteria
Unacceptable