1 / 9100%
The organization I chosen is the U.S. Department of Health & Human Services. The
contingency planning purpose is to lessen the damage of the risk when it occurs. Without the
plan in place, the full impact of the risk could greatly affect the project. The contingency
plan is the last line of defense against the risk. Risk assessment overall process or method
where; Identify hazards and risk factors that have the potential to cause harm hazard
identification. Analyze and evaluate the risk associated with that hazard risk analysis, and
risk evaluation. The steps involved in security planning for my organization are to assets are
items that have a value to the entity, including resources and property that are relied on to
sustain operations and capabilities. These are in addition to people and information
(including ICT) identified as critical to ongoing operations. Critical assets and components
of an asset are essential to the ongoing operation of the entity. Asset attractiveness is how a
threat source may view the asset in relation to the activity it seeks to undertake. Asset
attributes are the qualities that determine the nature and extent of impact on the entity
operations following an event or incident. For my chosen organization, google faces many
security issues and well in general. Firstly is accommodating to scaling availability causes
increased traffic this can cause downtime and maintenance which can cause need for patches
allowing exploits and zero days. Another issue which can cause the same results is they rely
on service providers, using third party providers can cause breaches in data. Ways to process
these threats to specifically data is that google already consists of cloud based storage this
reduces the chances of breaches and is a data loss preventive measure. According to googles
security policies they monitor suspicious activities on their networks, reviews security with
services, and periodic security assessments. Risk management is extremely critical for
google as it is such a widely used domain used worldwide. Any vulnerabilities or downtime
would exponentially affect the world falling under the cyber domain category. Confidential
data and data loss would be catastrophic as it's number of users is worldwide and is the most
used database. Existing threats and vulnerabilities are how risk management is constantly
updated and changing, because of it we have policies and prevention measures to keep
things secure. Anytime you deal with larger corporations or companies their are a ton of
vulnerabilities that could exist. In my case using Microsoft I would say that security for
individual users and their information stored is a big vulnerability that has been exploited in
the past. Although this breach might’ve been small compared to other companies it has
happened and can happen again. Most companies or corporations learn from the mistakes or
‘kinks’ in their armor to say and implement a stronger response with more security options.
Contingency planning, risk assessment, and finally risk control are very important to any
company when it comes to maintaining a degree of security and reliability in that company.
Considering how Microsoft is such a dominant technologies company it stands to reason that
they must defend themselves from any of the possible risks or issues involved with cyber
security and other cyber issues that may arise. I always ask myself what would happen if
Microsoft was unable to provide services for a single day or even a single hour. These are
things companies and corporations prepare for in risk assessment and risk control. The
organization that I chose in week one is my current employer, Bureau of Automotive Repair.
There are vulnerabilities in every organization, which is why risk management is such an
important factor in the security planning process. Vulnerabilities can come in any shape or
form whether its a physical or cyber risk. Every year, employees in my organization are
trained on what to do if a natural disaster occurred during working hours to avoid injury.
We're also trained on what to do if we received a bomb threat from a package or through the
phone whether it's just a prank. We have a team responsible for training every new employee
and we are even given the opportunity in taking classes to be first aid certified. The cyber
risks that occur with the organization that I work for consist of employees clicking on phishy
emails and links. This can cause a breach in our database and personal information from our
consumers can be obtained. To avoid this from happening, every employee who notices a
suspicious email is required to report it to our security team. The system is also overlooked
at the end of the day with a time duration of how long maintenance will be until we can
access our database again.
In my personal and professional opinion, all organizations and companies have
vulnerabilities. They are not always the same, but the risk will always be there. These risks
can be physical or online, as well as internal or external. These risks are never a good thing
for a company. They ultimately can cause anything from minor financial damage to the
whole business shutting down because of severe destruction. No one wants to have to deal
with these threats, but they are unavoidable. All you can do is have a plan in place to help
you through it when the time comes. I am continuing to run my research on the Sherwin-
Williams Company, and this company faces physical and cyber risks all over the world.
Some types of physical damage that can occur could be natural disasters as well as
robberies. Depending on what physical disaster occurs, the company could lose different
assets. The cyber risks are also a big deal in this company. Hackers can sometimes gain
traction on an internal server and start to download personal information. This information
could be financial information, product information, or employee’s personal information. No
one wants to have to deal with a data breach. Therefore, company’s need to be prepared with
a plan to avoid these threats, as well as deal with them. The three important steps go as
follows:
Step one: Perform Regulatory Review and Landscape. The company should first perform
regulatory review. This is where all the business requirements and industry standards are
assessed. This normal is looked at from outside the company.
Step two: Specify Governance, Oversight, and Responsibility. This is where the company
should create a computer information response team (CIRT) or computer information
security response team (CISRT). This team will be responsible of informing the company
and employees of the information security plan and making sure everyone follows it.
Step three: Take Inventory of Assets. This is the final step where you create an inventory of
both hardware and software. You can also keep track of existing safeguards and controls
currently in place. The level of security wont be assessed until this step is competed.
I think risk management is important part of the security planning process. This allows the
company to know itself and to know and plan for any risks that may happen and to assess
how much damage it can do to the organization. Also, this allows the organization to reduce
the level of risk to an acceptable level. I think the reading this week in chapter 5 explains it
perfectly. “The defenders attempt to prevent, protect, detect, and recover from a seemingly
endless series of attacks. Moreover, those defenders are legally prohibited from deploying
offensive tactics, so the attackers have no need to expend resources on defense. While the
defenders need to win every battle, the attackers only need to win once. To be victorious,
defenders must know themselves and their enemy.” The risks will always be there but with
risk assessment and management the overall fallout from the threat can be much less
damaging to the company and its customers. https://www.wbdg.org has a pretty good
example. Using an exterior explosive threat as an example, the installation of window
retrofits (i.e., security window film, laminated glass, etc.) will not prevent the explosive
attack from occurring, but it should reduce the impact of loss/injury caused by hazardous
flying glass. Therefore, the impact of loss rating for an explosive threat would improve, but
the vulnerability rating would stay the same.
Vulnerabilities can come at anytime time from a organization standpoint. Security is a
process that requires management and support for key areas of the organization. The
challenge is never-ending, and security teams have to cover different fronts through which
malicious code can infiltrate a network. A vulnerability that I believe would be a potential
threat are internal attacks. Internal attacks are one of the biggest threats facing your data and
systems, especially members with knowledge of and access to networks, data centers and
admin accounts, can cause serious damage. Careless and uninformed workers can be a risk
due to employees who are not trained in security best practices and have weak passwords,
visit unauthorized websites and/or click on links in suspicious emails or open email
attachments pose an enormous security threat.
Security management deals with how system integrity is maintained amid man-made threats
and risks, intentional or unintentional. Some Risk Management steps to put in place for the
organization would be:
Step1: Reevaluate IT assets and risks
Security management is a discipline that never rests. Major changes that would require a
reassessment of the security management practice include:
• Security violations are rampant.
• Organizational structure or composition changes.
• Business environment changes.
Step2: Analyze risk
Every effective security management system reflects a careful evaluation of how much
security is needed. Too little security means the system can easily be compromised
intentionally or unintentionally. Too much security can make the system hard to use or
degrade its performance unacceptably. Security is inversely proportional.
Step3: Implement security practices
Implement the security measures defined in the preceding step. You can do this in stages to
make it easier for everybody to adapt to the new working environment. Expect many
problems at the start, especially with respect to user resistance to their security tasks, such as
using passwords.
Vulnerabilities can be found in all organizations all around the world. Because of this
organizations and businesses should be managing risk responsibly and considering all
possible threats and maintain a mentality that it’s not if something happens it when
something goes wrong. There should be different plans of action and preparation covering
all the potential threats and hazards such as physical, social and cyber. The department I
work in mainly puts a large focus on privacy and avoiding data breaches, so I’m not deeply
versed in the procedures regarding physical threats. But I understand the importance of risk
management in all of its forms and have a basic understanding of planning for a disaster.
You will start by staying up to code so to speak, making sure that you are meeting industry
standard and meeting all the requirements of your organization and its governing bodies
including SLA's. They would do this by setting up the proper policies and procedures. Your
next move is assigning responsibility and leadership roles. Your response teams should help
with making sure the policies put into place are being followed. You’d do this in the form of
response teams like a CIRST and a CIRT. Your final step is keeping proper documentation
on your inventory and assets, whether that be hardware or software. And having strong
backups in place in case there is a loss of information due to disaster. When it comes to
vulnerabilities all organizations have them in one form or another regardless the type of
organization. Risks come in different forms whether it is physical or cyber, either one can
cause severe damage to an organization costing them severally financially. The company I
decided to research run the risk of physical and cyber risks to all 3 locations they currently
have. When it comes to physically threats, the offices are at risk of natural disaster and man-
made attacks such as flooding, wildfires, earthquakes, and possible car collision to the
building. If any physical disaster were to occur it would cause equipment and data loss such
as the desktops used by employees and the servers where all the information is stored. Along
with physical risks, cyber risks are can be a financial burden; some cyber risks would
include hackers, trojan attack, or a server going down due to internal failure. Risk
management is an important part of security planning for an organization, the steps go as
follow;
Step one: perform regulatory review and landscape – the firm must perform a regulatory
review; all businesses have requirements from oversight bodies along with self-imposed
industry standards and expectations coming from external stake holders.
Step two: specify governance, oversight, and responsibility – Create a Computer Information
Response Team (CIRT) or Computer Information Security Response Team (CISRT). The
team will be responsible to ensure the firm follows policy and procedures from the
information security plan.
Step three: take inventory of assets – create an inventory of both hardware, and software as
well as identify existing safeguards and controls currently in place. The firm’s level of risk
can not be assessed properly without this step.
Information security risk management, or ISRM, is the process of managing risks associated
with the use of information technology. It involves identifying, assessing, and treating risks
to the confidentiality, integrity, and availability of an organization's assets. An information
security plan is documentation of a firm's plan and systems put in place to protect personal
information and sensitive company data. This plan can mitigate threats against your
organization, as well as help your firm protect the integrity, confidentiality, and availability
of your data.
Following are some of the steps to create an Information Security Plan:
Step 1: Perform a Regulatory Review and Landscape
Your firm must first perform a regulatory review, as all businesses have requirement coming
from oversight bodies. There are also self-imposed industry standards and expectations that
come from external stakeholders.
Step 2: Specify Governance, Oversight & Responsibility
Create a CIRT (Computer Information Response Team). This group will be responsible for
ensuring the firm follows the policy and procedures around the information security plan.
Step 3: Take Inventory of Assets
Know what you have means create an inventory of both hardware and software and identify
existing safeguards and controls you have in place. This step is crucial, as you can't properly
assess your firm's level of risk or adequately protect data and information unless you
understand what systems you have and what data they hold.
All facilities face a certain level of risk associated with various threats. These threats may be
the result of natural events, accidents, or intentional acts to cause harm. Regardless of the
nature of the threat, facility owners have a responsibility to limit or manage risks from these
threats to the extent possible.
When it comes to risk management, there are a lot of different risks that could potentially
cause harm. When assessing the risks for the organization there is a lot that goes into the risk
analysis. We consider not only virtual harm but physical harm as well. I am not sure the
exact details on what types of prcautions are taken on the cyber side of things. I do however
know that the branch that I work at is a hot site backup for the branch down in Louisiana.
The place that I work is where we ship oil for the company. If the site in Louisiana is hit by
a natural disaster such as a hurricane, they would send all of there orders and processing
needs to us. This happened a few years ago when I was first starting there and we had to
cover their needs until they made the necessary repairs to the facility and they could get back
up and running. There are all kinds of security threats to deal with on the cyber side. Since
the organization is a quite large one the risks are always surrounding it. One risk
management strategy that they have implemented is setting up 2 offsite backups that are
always running and always ready to take over when a disaster hits. We have the main
headquarters in the UK which is the primary. This is where everything is run from normally.
They have a main office that is in NJ and then another in Toronto. If the main facility in the
UK goes down or is hit with a disaster, the office in NJ can take over the operations as if
nothing had ever happened. The same goes with the office in Toronto since they are all the
main offices for the 3 different countries.
Students also viewed