Reference no: EM132215395
Assignment
This assignment requires you to complete a cyber risk mitigation strategy for Sony Pictures Entertainment organization. You are required to create a risk mitigation strategy that the organization should have followed in light of the 2014 hack.
Introduction
Write a brief paragraph in which you provide a high-level overview of SPE need for a risk mitigation strategy.
(150 words)
Vision
Outline SPE's vision of what implementing a risk mitigation strategy will ideally achieve.
(150 words)
Strategic goals and objectives
List at least four strategic goals SPE must achieve to reduce its risks to an acceptable level. List at least two objectives under each strategic goal that explain what must be done to achieve the strategic goal.
Note: A thorough risk mitigation strategy should include associated action plans and milestones, but you are not required to detail these for the purposes of this submission.
(450 words)
Metrics
List at least three metrics SPE will use to analyze the achievement of its goals/objectives. These metrics should be specific to the goals/objectives listed in the previous question.
(150 words)
Threat actors and methods of attack
Integrate your submission from Module 2, in which you identified at least two threat actors to SPE, and described methods of attack these actors could use.
If you are using the Sony case, integrate the submission in which you identified the threat actor Sony faced in the 2014 hack and their method of attack, as well as at least one other threat actor Sony could face in the future and what method of attack they might use.
(550 words)
Business critical assets
identified the assets that are most essential to Sony's ability to accomplish its mission. Describe what vulnerabilities there may be in SPE's systems, networks, and data that may put these assets at risk.
(550 words)
Cybersecurity governance
Integrate the three questions from your Assignment, in which you recommended a cybersecurity leadership plan, improvements to management processes, and a cybersecurity awareness training program.
(1,200 words)
Protective technologies
In one of your submission, you compiled a list of questions you would ask to understand the technologies implemented to protect your organization's critical systems, networks, and data. In this section, based on the questions you asked and by conducting any other additional research, identify technologies your organization can employ to protect its critical systems, networks, and data.
If you are using the Sony case, recommend protective technologies that could have addressed Sony's shortcomings in protecting their critical networks, systems, and data.
(650 words)
Legal considerations
research discuss the legal considerations SPE should considerwhen compiling its risk mitigation strategy. recommend steps that could have addressed Sony's shortcomings in protecting themselves from legal action.