Identify security control or countermeasure to mitigate risk

Assignment Help Computer Engineering
Reference no: EM133473141

Assignment: Security Policy and Standards

Part A: Research Remote Access Policies

Note: In this part of the lab, you will review internet resources on remote access policies in order to form a basis for their purpose and usage. Understanding the reason behind a remote access policy is key to understanding the component policies and procedures. Please take the time to review the research thoroughly and think through the concepts of the policy itself.

I. In your browser, navigate to and read the "Remote Access Policy" template at https://www.sans.org/information-security-policy/.

II. Using your favorite search engine, locate a remote access policy for a higher education institution.

III. Using your favorite search engine, locate a remote access policy for a healthcare provider.

IV. Write a brief summary of the information during your research. In your summary, focus on the key elements of the remote access policy. You should also identify any unique elements of remote access policies for higher education and healthcare institutions. Be sure to provide links to the remote access policies you identified in steps 2 and 3.

Part B: Create a Remote Access Policy

Note: As you found in your research, different industries have similar but different policies. When using a policy template, it is important to ensure that the template matches the needs of your specific industry and business.

I. Review the following risks and threats found in the Remote Access Domain:

1. The organization is a local credit union that has several branches and locations throughout the region.

2. Online banking and use of the internet are the bank's strengths, given its limited human resources.

3. The customer service department is the organization's most critical business function.

4. The organization wants to be in compliance with the Gramm-Leach-Bliley Act (GLBA) and IT security best practices regarding its employees.

5. The organization wants to monitor and control use of the internet by implementing content filtering.

6. The organization wants to eliminate personal use of organization-owned IT assets and systems.

7. The organization wants to monitor and control use of the e-mail system by implementing e-mail security controls.

8. The organization wants to implement security awareness training policy mandates for all new hires and existing employees. Policy definitions are to include GLBA and customer privacy data requirements, in addition to a mandate for annual security awareness training for all employees.

II. Identify a security control or countermeasure to mitigate each risk and threat identified in the Remote Access Domain. These security controls or countermeasures will become the basis of the scope of the Remote Access Domain policy definition to help mitigate the risks and threats commonly found within the Remote Access Domain.

III. Review the following characteristics of the fictional Healthwise Health Care Provider:

1. Healthwise has several remote health care branches and locations throughout the region.

2. Online access to patients' medical records through the public Internet is required for remote nurses and hospices providing in-home medical services.

3. Online access to patients' medical records from remote clinics is facilitated through a virtual private network (VPN) and a secure web application front-end over the public Internet.

4. The organization wants to be in compliance with the Health Insurance Portability and Accountability Act (HIPAA) and IT security best practices regarding remote access through the public internet.

5. The organization wants to monitor and control the use of remote access by implementing system logging.

6. The organization wants to implement a security awareness training policy mandating that all new hires and existing employees obtain remote access security training. Policy definition is to include HIPAA and electronic protected health information (ePHI) security requirements and a mandate for annual security awareness training for all remote or mobile employees.

IV. Create an organization-wide remote access policy for Healthwise Health Care:

1. Healthwise Health Care

Remote Access Policy for Remote Workers and Medical Clinics

2. Policy Statement

Define your policy verbiage.

3. Purpose/Objectives

Define the policy's purpose as well as its objectives and policy definitions

4. Scope

Define whom this policy covers and its scope. What elements, IT assets, or organization-owned assets are within this policy's scope?

5. Standards

Does the policy statement point to any hardware, software, or configuration standards? If so, list them here and explain the relationship of this policy to these standards. In this case, Remote Access Domain standards should be referenced, such as encryption standards and VPN standards; make any necessary assumptions.

6. Procedures

Explain how you intend to implement this policy for the entire organization.

7. Guidelines

Explain any roadblocks or implementation issues that you must overcome in this section and how you will surmount them per defined guidelines. Any disputes or gaps in the definition and separation of duties responsibility may need to be addressed in this section.

8. Challenge Exercise

Note: The following challenge exercise is provided to allow independent, unguided work - similar to what you will encounter in a real situation.

For this portion of the lab, you will create training documentation for remote employees of Healthwise Health Care. This training will provide remote employees with methods they can use to secure their home network before connecting a company computer, as well as guidance on how to access the corporate network while traveling.

Use the internet to find information about remote access policies and home network protection, and then use this information to create a training document for remote employees.

Reference no: EM133473141

Questions Cloud

Explain the seasonal cycles of life : Identify and briefly explain the main differences between the "Treaty with the Chippewa, 1837," and the "Treaty with the Sioux, Sisseton and Wahpeton Bands
Discuss eight central risk and needs factors of offenders : If you believe that it should be considered when determining an offender's sentence, describe how the eight central risk and needs assessments could be useful.
What would an investor look for in a company financial : What would an investor look for in a company's financial statements? - ACG 6175 FIU Business Assessing Financial Accounts
Identify current real world scenario : Identify current real world scenario that illustrates conflict around the right, and describe the reasons explaining the different sides of the conflict
Identify security control or countermeasure to mitigate risk : Identify a security control or countermeasure to mitigate each risk and threat identified in the Remote Access Domain.
Discuss digital evidence is stored at police stations : Discuss the process utilized by police forensic investigators to remove digital evidence from a crime scene.
Why and how did colonists protest against the stamp act : Why and how did Colonists protest against the Stamp Act and the Townsend Acts. Were they ready for independence after the Boston Massacre
Explain which law of motion is used and explain in detail : explain which law of motion is used and explain in detail any associated forces, masses, accelerations, etc. Note that this will be a general description
What do you think this statement means : What do you think this statement means? Bring in at least two artists that were covered in this course to back up your argument

Reviews

Write a Review

Computer Engineering Questions & Answers

  Create a implementation file containing the member function

Create a specification file containing the declaration of the VerifyDate class. Create a implementation file containing the member function definitions for VerifyDate.

  How an interrupt handler would address the event

Set the context for the interrupt disk read and describe how an interrupt handler would address the event.

  Explain why dfs trees cannot contain cross edges it may

a explain how a dfs can be used to look for cycles in a graph.b explain why dfs trees cannot contain cross edges. it

  What conclusion, if any, can be reached

what conclusion, if any, can be reached from the given hypotheses and justify your answer. 1. All flowers are plants. Pansies are flowers.

  Write a recursive java function

CPSC 327, Homework. Write a recursive Java function, void max( int[] A, int lo, int hi ), that finds the maximum value among the array elements

  What are the merits of flash memory over hard disk storage

what are the advantages of flash memory over hard disk storage? what are the advantages of hard disk over flash memory

  To what percent of its normal speed is the computer reduced

To what percent of its normal speed is the computer reduced during a DMA transfer if each 32-bit DMA transfer takes one bus cycle?

  How to prevent a common application software attack

The objective will focus on protecting Microsoft application, which could make the operating systems vulnerable. Also, we will focus on the principle.

  What are the core competencies of the company

Papers will consist of 3- pages of content, using a formal writing style based on APA 6th edition, 7th printing guidelines.

  Explain the importance of setting up a learning rate

Explain the importance of setting up a learning rate in the gradient descent-based methods. What is stochastic gradient descent? Why do we need stochastic

  Write a program that prints range of a sequence of integers

Write a program that prints the range of a sequence of integers provided through stdin. For example, the range of -3, 15, -8, 29, 17 is 29 - (-8) = 37.

  Enable network connectivity

Many LANs requires both wired and wireless connectivity. Compare the appropriateness of different media types which may be used to enable network connectivity

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd