Information Security Risk Management assignment
Information Security Risk Management
ITC6315
Assignment 4
Assignment
For this exercise, read the provided case study about AcmeHealth, and complete the following tasks:
1. For each of the findings, recommend a reasonable action plan that would address the risk. Follow the example of the right-hand column in the assignment sample below.
2. You can use the controls we have discussed in class or suggest your own
Assume that you may be filing a short- or long-term exception along with your action plan, so you will need to specify the mitigation steps that will be taken to lower the risk of each finding. Be sure to state the Action Item in the form of an action statement, such as “Contact …”, “Implement …”, “Enforce …”, etc. Review the provided example as a guideline.
As you are deciding which controls would be most appropriate to mitigate the risk, consider the environment and total cost of the controls. If you feel it would be more efficient not to implement a control, offer an alternative risk strategy such as acceptance or buying insurance (transference). Also account for any existing controls that the organization already has in place. Both technical and non-technical controls may be appropriate for this exercise.
If you don’t understand the technical details of any of the findings, please post questions to the Discussion Forum and ask the instructor to clarify.
You can turn in the assignment electronically through Blackboard.
The following sample findings and mitigation plans illustrate how each plan should be listed and described:
Finding:
Finding: All internet links are serviced by a single ISP
Risk Exposure: High
Mitigation Plan: Contract with at least two different service providers in order to maintain availability in the case of a major ISP failure.
Target Date: End of Q2 2012 Responsible Party(ies): IT Department
Finding:
Finding: Not all backup copies of sensitive data are encrypted
Risk Exposure: High
Mitigation Plan: All stored sensitive data should be encrypted, including backups on-site and off-site.
Target Date: Within 30 Days Responsible Party(ies): IT Department
Finding:
Finding: Updates to the file server are not tested before implementation
Risk Exposure: Moderate
Mitigation Plan: Establish a small test environment to verify any new updates before installing them in production. This test environment should mimic the production file server configuration as closely as possible.
Establish a roll-back plan for each update made to the production system.
Target Date: Within 90 Days Responsible Party(ies): QA Testing Team and System Administrators
Finding:
Finding: Router brands and software versions are listed on job postings
Risk Exposure: Low
Mitigation Plan: In job postings, try to limit infrastructure details and desired competencies to generic platform references or specific industry certifications like CCNA. Include this in security guidelines and employee security awareness training.
Target Date: End of Q4 2012 Responsible Party(ies): HR Department and Security Team
Record your mitigation plans target dates and responsible parties in the space provided below. Reference the finding numbers and your assessments from Assignment 3:
Finding 2:
Finding: Network connections from the offshore developers’ workstations to the code repository server are not encrypted.
Risk Exposure: ________________
Mitigation Plan: _______________________________________________________________________
_______________________________________________________________________________________
_______________________________________________________________________________________
_______________________________________________________________________________________
_______________________________________________________________________________________
Target Date: ________________ Responsible Party(ies): _________________________
Finding 4:
Finding: Client data is copied from production servers to this server regularly for QA testing.
Risk Exposure: ________________
Mitigation Plan: _______________________________________________________________________
_______________________________________________________________________________________
_______________________________________________________________________________________
_______________________________________________________________________________________
_______________________________________________________________________________________
Target Date: ________________ Responsible Party(ies): _________________________
Finding 6:
Finding: No one notifies the Help Desk of terminations for support personnel in order to ensure that their access is disabled.
Risk Exposure: ________________
Mitigation Plan: _______________________________________________________________________
_______________________________________________________________________________________
_______________________________________________________________________________________
_______________________________________________________________________________________
_______________________________________________________________________________________
Target Date: ________________ Responsible Party(ies): _________________________