SEC 402– Cyber security
Week 5
2nd October
Assignment 5: Healthcare IoT Security for a Hospital Network
Due Week 5 and worth 75 points
Instructions: You are a cybersecurity consultant working with a hospital to enhance the security
of its Internet of Things (IoT) devices, including medical devices and healthcare equipment.
Write a seven to nine-page paper addressing the following questions:
1. Identify and analyze security risks associated with IoT devices in a healthcare
environment. Discuss potential threats, vulnerabilities, and the impact of security
breaches on patient safety and data privacy.
2. Propose strategies for authenticating and controlling access to medical devices. Discuss
the importance of securing networked medical equipment and ensuring that only
authorized personnel can interact with these devices.
3. Evaluate the security of patient records stored and transmitted by IoT devices.
Recommend measures to ensure the integrity and confidentiality of patient data,
including encryption and secure data transmission.
4. Develop a training program for hospital staff on IoT security best practices. Discuss the
role of staff awareness in preventing cybersecurity incidents and fostering a culture of
security within the healthcare environment.
5. Develop an incident response plan specifically tailored for security incidents involving
IoT devices in a healthcare setting. Discuss coordination with medical staff,
communication strategies, and steps to minimize the impact of incidents on patient care.
Ensure that your papers provide practical recommendations and considerations for the specified
scenarios. Use relevant industry standards, best practices, and case studies to support your
analysis and suggestions.
Your assignment must follow these formatting requirements:
Be typed, double spaced, using Times New Roman font (size 12), with one-inch margins
on all sides; citations and references must follow APA or school-specific format. Check
with your professor for any additional instructions.
Include a cover page containing the title of the assignment, the student’s name, the
professor’s name, the course title, and the date. The cover page and the reference page
are not included in the required assignment page length.
The specific course learning outcomes associated with this assignment are:
Compare and contrast the methods of disaster recovery and business continuity.
Explain risk management in the context of information security.
Use technology and information resources to research issues in disaster recovery.
Write clearly and concisely about disaster recovery topics using proper writing
mechanics and technical style conventions.
Grading for this assignment will be based on answer quality, logic / organization of the paper,
and language and writing skills, using the following rubric.
Points: 75 Assignment 5: Healthcare IoT Security for a Hospital Network
Criteria Unacceptable
Below 60% F
Meets
Minimum
Expectations
60-69% D
Fair
70-79% C
Proficient
80-89% B
Exemplary
90-100% A
1. Explain the basic
primary tasks, ongoing
evaluations, and major
policy and procedural
changes that would be
needed to perform as
the BC lead / manager.
Weight: 20%
Did not submit or
incompletely
explained the
basic primary
tasks, ongoing
evaluations, and
major policy and
procedural
changes that
would be needed
to perform as the
BC lead /
manager.
Insufficiently
explained the
basic primary
tasks, ongoing
evaluations,
and major
policy and
procedural
changes that
would be
needed to
perform as the
BC lead /
manager.
Partially
explained the
basic primary
tasks, ongoing
evaluations,
and major
policy and
procedural
changes that
would be
needed to
perform as the
BC lead /
manager.
Satisfactorily
explained the
basic primary
tasks, ongoing
evaluations,
and major
policy and
procedural
changes that
would be
needed to
perform as the
BC lead /
manager.
Thoroughly
explained the
basic primary
tasks, ongoing
evaluations,
and major
policy and
procedural
changes that
would be
needed to
perform as the
BC lead /
manager.
2. Provide insight on