Reference no: EM132314689 , Length: word count:3000
Assignment -
Learning Objectives -
- Evaluate, synthesise and critically review theoretical frameworks with other evidence to provide solutions to real-world problems by applying security management models and practices to security programs.
- Demonstrate an understanding of change on organisations in the global environment and the impact of these on organisational systems by developing risk management strategies that incorporate appropriate controls.
- Demonstrate an understanding of the impact of interpersonal communication on specific management processes and outcomes using relevant theories and concepts by understanding the relationships between security and personnel, between security and law, between security and ethics.
- Demonstrate an understanding of change on organisations in the global environment and the impact of these on organisational systems by developing risk management strategies that incorporate appropriate controls.
Introduction - Business disruptions can take place everywhere, anytime. It is impossible to foresee what may hit and when. It has become compulsory for organizations to be organized for such disaster/recovery scenarios. With the ever-increasing dependence on business processes for both electronic and traditional services, it has become almost mandatory for every organization to plan also for Business Continuity (BCP). Consider the earthquake disaster case below:
Case Study: Earthquake
At 12:51 p.m. on Tuesday February 2011, an earthquake of 6.3 magnitude hit Canterbury causing severe damage in Christchurch and Lyttleton. The epicentre was just ten kilometres near Lyttleton, which is south-east of Christchurch's central business district. It was worst as compared to the ones hot in 2010 because it occurred at a time, when maximum number of people were on the streets. Many fatalities were reported due to collapsing buildings as well as falling debris. Damage to business structures, the Canterbury Television, Pyne Gould Corporation buildings. It brought down many already weakened structures like older brick and mortar buildings. Many heritage buildings, including the Provincial Council Chambers, Lyttleton's Time ball Station, and both the Anglican Christchurch Cathedral and the Catholic Cathedral of the Blessed Sacrament were heavily damaged. Among the modern buildings irrevocably damaged was Christchurch's tallest building, the Hotel Grand Chancellor. More than half of the buildings in the central business district have had to be demolished.
This earthquake occurred on a fault line that was shallow and close to the city, so the shaking was particularly destructive. The fault movement and structure of the bedrock produced exceptionally strong ground motion due to gravity in the eastern suburbs and in city it was three to four times greater than those produced by the September 2010 earthquake. Also, the liquefaction was much more extensive. Eastern sections of the city were built on a former swamp. Shaking turned water- saturated layers of sand and silt beneath the surface into sludge that squirted upwards through cracks. Properties and streets were buried in thick layers of silt, and water and sewage from broken pipes flooded streets. House foundations cracked and buckled, wrecking many homes. Despite the damage, there were few serious injuries in residential houses in liquefaction areas. However, several thousand homes will have to be demolished, and some sections of suburbs will probably never be reoccupied.
Tasks -
Part 1 - IT Disaster Recovery and Business Continuity Plan
You are required to choose a global multinational company based in New Zealand. Your chosen organization must fulfill the following criteria:
- The organization may be a commercial, government or not-for-profit organisation but it must have at least 50 employees, a web site and be a user of e-business/e-commerce
- Use the web, newspapers and/or personal contacts to gain information about the organisation and its management of IT
- When selecting the organization, you should consider the nature of the organisation's business environment and the extent to which the organisation is dependent on IT to run its operations
Complete the requirements below by producing a written report to the CEO.
Task 1: Introduction: background of selected organisation - Describe the background of the selected organisation in terms of the following: the industry (e.g. banking, healthcare, travel, airline etc.) it operates within, its key products/ services, corporate mission, corporate structure, major business processes, business strategy and relationship with external entities e.g. other organisations, government etc. Provide its homepage URL
Task 2: Analyse the earthquake case study above and develop a disaster recovery plan for the Information Systems of your organisation. Your plan must cover both infrastructures (e.g. IT infrastructure) and human resources (e.g. partners, client and employees).
Task 3: Provide a clear description supported with visuals of how various virtualization technologies can be leveraged to reorganize and restore servers, network and storage resources for the critical applications used by your chosen organisation. It is important that you consider critical aspects of the organisation's business functions and identify business priorities in this case.
Tasks 4: Provide detail business impact analysis of your plan. You are encouraged to use graphs, figures and sample data to present your analysis. These must reflect the financial viability of your proposed DRP solution.
Task 5: Using Microsoft PowerPoint, develop a professional presentation to the CISO to convince him/her to provide the appropriate resources to realize the development and implementation your plan. Maximum number of PowerPoint slides is 20 (twenty) and must capture details of your plan. (Note: There will be oral presentation for this part).
Part 2 - Information security risk management, programs and models
According to the Sermelles Limited scenario, which was introduced in Assessment 1, you have already analysed the security situation of the scenario. A research report was also prepared by you that provided details about security issues and policies for the Sermelles Limited security improvements, etc. Use the Sermelles Limited scenario for this assessment as well.
Given the Sermelles Limited scenario, you now need to develop the following:
- Develop a security program based on the size of the Sermelles Limited organization (small/medium/large)
- Provide risk assessment and risk control for this organization.
- Identify the most suitable ISO security standards and model for this organization. You need to provide justification why you have selected a standard and /or model for the organization.
- Reflect on the case and recommend a strategy to enhance the existing security framework of Sermelles Limited.
Attachment:- Assignment File - Case Study.rar