Reference no: EM133422146
Project Scenario
You are a third party security consultant hired by the hospital to perform a security audit and make recommendations for remediation. Your customer is a hospital organization responsible for providing patient care to over 1 million patients annually. This hospital was a national leader in providing patient care to a major metropolitan area. Recently, a data breach occurred within the enterprise resulting in significant patient information being breached. This breach was identified by a (different) security researcher, unaffiliated with the hospital, by finding data posted on dark web markets. This event became publicly known and the hospital's reputation has been tarnished as a result. To remediate, the organization has allocated significant funds to overhaul their network and cyber security. To begin, the hospital CISO hired you to conduct a thorough audit of the environment. The hospitals IT architecture consists of a campus WAN with three main office buildings operating inside of the campus network; the main hospital, the children's hospital, and the research and administrative building. During the audit, there were many findings inside of the organization that included: Numerous HIPAA violations around data security and handling. Multiple accounts with unnecessary administrative privileges. Sensitive areas of the environment that were not segregated from the rest of the network (i.e. a flat network). Remote employees had access to sensitive resources from outside the organization without the use of any secure means of access. Physical areas of the IT facilities were not secured or otherwise easily accessible. Hundreds of endpoints that were not updated with the latest OS and patches. Weak or default passwords in use across the network with no multi-factor authentication. Poor documentation with generic policies and standards. The action is on your team to develop a project plan, and presentation to key leadership on how best to mitigate each of these findings. If the approach and design strategy are approved by the executive leadership, you may receive additional business for carrying out these remediations.
Additional Notes I highly recommend you research HIPAA compliance and checklist documentation. Specifically, around the areas of data handling and classifications. The network architecture and design is intentionally vague.
Describe in twenty five thousand word to discuss your proposed plan.
The action is on your team to develop a project plan, and presentation to key leadership on how best to mitigate each of these findings. If the approach and design strategy are approved by the executive leadership, you may receive additional business for carrying out these remediations.
What are some other modes of access that users might want
: What are some other modes of access that users might want to apply to code or data, in addition to the common read, write, and execute permission
|
What makes this article reliable
: summarize what it's about in 3 senetences. what age group is this article about? what makes this article reliable?
|
Explain why it is difficult to validate the relationships
: Explain why it is difficult to validate the relationships between internal product attributes, such as cyclomatic complexity and external attributes
|
Explain how each of the aspects potentially impacts your own
: Explain how each of the aspects potentially impacts your own outward communication. Explain how, f you known and understood, it may impact how others
|
Discuss your proposed plan
: Describe in twenty five thousand word to discuss your proposed plan - design strategy are approved by the executive leadership, you may receive additional
|
What are the qualities of a good leader
: What are the qualities of a good leader? What does leadership mean and how have you demonstrated it ? Minimum length for the essay is 150 words essay
|
What characteristics of children with concrete operations
: Apply your knowledge of Piagetian theory in the following situation: You are a science teacher whose students have just begun to use formal operations.
|
Common and ubiquitous applications like military recon
: Common and ubiquitous applications like military recon and surveillance, construction/inspection, SaR, LEO, Agriculture, Firefighting, etc, should not be part
|
What are four exceptionalities that you have learned about
: What are four exceptionalities that you have learned about in this lesson? Thoroughly discuss each of their characteristics and discuss ways to ensure that you
|