Information Security Risk Management assignment

profilejasjas
assignment_41.doc

image1.png

Information Security Risk Management

ITC6315

Assignment 4

Assignment

For this exercise, read the provided case study about AcmeHealth, and complete the following tasks:

1. For each of the findings, recommend a reasonable action plan that would address the risk. Follow the example of the right-hand column in the assignment sample below.

2. You can use the controls we have discussed in class or suggest your own

Assume that you may be filing a short- or long-term exception along with your action plan, so you will need to specify the mitigation steps that will be taken to lower the risk of each finding. Be sure to state the Action Item in the form of an action statement, such as “Contact …”, “Implement …”, “Enforce …”, etc. Review the provided example as a guideline.

As you are deciding which controls would be most appropriate to mitigate the risk, consider the environment and total cost of the controls. If you feel it would be more efficient not to implement a control, offer an alternative risk strategy such as acceptance or buying insurance (transference). Also account for any existing controls that the organization already has in place. Both technical and non-technical controls may be appropriate for this exercise.

If you don’t understand the technical details of any of the findings, please post questions to the Discussion Forum and ask the instructor to clarify.

You can turn in the assignment electronically through Blackboard.

The following sample findings and mitigation plans illustrate how each plan should be listed and described:

Finding:

Finding: All internet links are serviced by a single ISP

Risk Exposure: High

Mitigation Plan: Contract with at least two different service providers in order to maintain availability in the case of a major ISP failure.

Target Date: End of Q2 2012 Responsible Party(ies): IT Department

Finding:

Finding: Not all backup copies of sensitive data are encrypted

Risk Exposure: High

Mitigation Plan: All stored sensitive data should be encrypted, including backups on-site and off-site.

Target Date: Within 30 Days Responsible Party(ies): IT Department

Finding:

Finding: Updates to the file server are not tested before implementation

Risk Exposure: Moderate

Mitigation Plan: Establish a small test environment to verify any new updates before installing them in production. This test environment should mimic the production file server configuration as closely as possible.

Establish a roll-back plan for each update made to the production system.

Target Date: Within 90 Days Responsible Party(ies): QA Testing Team and System Administrators

Finding:

Finding: Router brands and software versions are listed on job postings

Risk Exposure: Low

Mitigation Plan: In job postings, try to limit infrastructure details and desired competencies to generic platform references or specific industry certifications like CCNA. Include this in security guidelines and employee security awareness training.

Target Date: End of Q4 2012 Responsible Party(ies): HR Department and Security Team

Record your mitigation plans target dates and responsible parties in the space provided below. Reference the finding numbers and your assessments from Assignment 3:

Finding 2:

Finding: Network connections from the offshore developers’ workstations to the code repository server are not encrypted.

Risk Exposure: ________________

Mitigation Plan: _______________________________________________________________________

_______________________________________________________________________________________

_______________________________________________________________________________________

_______________________________________________________________________________________

_______________________________________________________________________________________

Target Date: ________________ Responsible Party(ies): _________________________

Finding 4:

Finding: Client data is copied from production servers to this server regularly for QA testing.

Risk Exposure: ________________

Mitigation Plan: _______________________________________________________________________

_______________________________________________________________________________________

_______________________________________________________________________________________

_______________________________________________________________________________________

_______________________________________________________________________________________

Target Date: ________________ Responsible Party(ies): _________________________

Finding 6:

Finding: No one notifies the Help Desk of terminations for support personnel in order to ensure that their access is disabled.

Risk Exposure: ________________

Mitigation Plan: _______________________________________________________________________

_______________________________________________________________________________________

_______________________________________________________________________________________

_______________________________________________________________________________________

_______________________________________________________________________________________

Target Date: ________________ Responsible Party(ies): _________________________