Reference no: EM133337657
Assignment:
You are a member of the cybersecurity team at Develetech Industries, a manufacturer of home electronics located in the fictitious city and state of Greene City, Richland (RL). The CEO has recently placed you in charge of reviewing your enterprise security strategies following the principle of risk management. When you can identify just how risk negatively affects your enterprise, you'll be able to convince your employer, your team, and the rest of your employees of the importance of managing that risk.
1. Develetech, a relatively large electronics manufacturer, is looking to expand its business domestically and internationally over the next couple of years. This may include everything from taking on new staff to establishing additional offices and warehouses. Why would these changes necessitate the development of an ERM strategy?
2. You've identified a risk to the availability of your file servers at peak traffic hours. How would you prefer to calculate Develetech's risk exposure in this area? What are the strengths and weaknesses of the analysis you've chosen, and why do you think it's more beneficial than the others?
3. One of the possibilities involved in expanding Develetech is the adoption of new technology. Your CEO may decide to drop legacy products or even drop certain vendors altogether and replace them. What are the important things to remember about assessing new products and technologies, along with threats that inevitably come with them?
4. Your team at Develetech has been busy assessing the various risks that could affect the company. Now it's time for you to analyze these results and respond appropriately. Choosing the right risk mitigation strategies is essential in meeting stakeholder expectations and keeping your systems secure at the same time. During their risk assessment, your team has identified a security flaw in an application your organization developed. To conduct a proper analysis of how this could bring risk to your enterprise, what are some of the questions you need to ask?
5. You've analyzed the application flaw and discovered that it could allow an unauthorized user to access the customer database that the app integrates with, if the app uses poor input validation. If an attacker were to access the database this way, they could glean confidential customer information, which would have a high impact on your business. However, you determine that your app's current input validation techniques account for all known exploits of this kind. How will you respond to this risk?