Maintaining the it security strategy in organizations

Assignment Help Risk Management
Reference no: EM132275408

You are employed with Government Security Consultants, a subsidiary of Largo Corporation. As a member of IT security consultant team, one of your responsibilities is to ensure the security of assets as well as provide a secure environment for customers, partners and employees. You and the team play a key role in defining, implementing and maintaining the IT security strategy in organizations.

A government agency called the Bureau of Research and Intelligence (BRI) is tasked with gathering and analyzing information to support U.S. diplomats.

In a series of New York Times articles, BRI was exposed as being the victim of several security breaches. As a follow up, the United States Government Accountability Office (GAO) conducted a comprehensive review of the agency's information security controls and identified numerous issues.

The head of the agency has contracted your company to conduct an IT security risk assessment on its operations. This risk assessment was determined to be necessary to address security gaps in the agency's critical operational areas and to determine actions to close those gaps. It is also meant to ensure that the agency invests time and money in the right areas and does not waste resources. After conducting the assessment, you are to develop a final report that summarizes the findings and provides a set of recommendations. You are to convince the agency to implement your recommendations.

This learning activity focuses on IT security which is an overarching concern that involves practically all facets of an organization's activities. You will learn about the key steps of preparing for and conducting a security risk assessment and how to present the findings to leaders and convince them into taking appropriate action.

Understanding security capabilities is basic to the core knowledge, skills, and abilities that IT personnel are expected to possess. Information security is a significant concern among every organization and it may spell success or failure of its mission. Effective IT professionals are expected to be up-to-date on trends in IT security, current threats and vulnerabilities, state-of-the-art security safeguards, and security policies and procedures. IT professionals must be able to communicate effectively (oral and written) to executive level management in a non-jargon, executive level manner that convincingly justifies the need to invest in IT security improvements. This learning demonstration is designed to strengthen these essential knowledge, skills, and abilities needed by IT professionals.

Steps to Completion

Your instructor will form the teams. Each member is expected to contribute to the team agreementwhich documents the members' contact information and sets goals and expectations for the team.

1) Review the Setting and Situation

The primary mission of the Bureau of Research and Intelligence (BRI) is to provide multiple-source intelligence to American diplomats. It must ensure that intelligence activities are consistent with U.S. foreign policy and kept totally confidential. BRI has intelligence analysts who understand U.S. foreign policy concerns as well as the type of information needed by diplomats.

The agency is in a dynamic environment in which events affecting foreign policy occur every day. Also, technology is rapidly changing and therefore new types of security opportunities and threats are emerging which may impact the agency.

Due to Congressional budget restrictions, BRI is forced to be selective in the type of security measures that it will implement. Prioritization of proposed security programs and controls based on a sound risk assessment procedure is necessary for this environment.

The following incidents involving BRI's systems occurred and reported in the New York Times and other media outlets:
- BRI's network had been compromised by nation-state-sponsored attackers and that attacks are still continuing. It is believed that the attackers accessed the intelligence data used to support U.S. diplomats.
- The chief of the bureau used his personal e-mail system for both official business purposes and for his own individual use.
- A software defect in BRI's human resource system - a web application - improperly allowed users to view the personal information of all BRI employees including social security numbers, birthdates, addresses, and bank account numbers (for direct deposit of their paychecks). After the breach, evidence was accidently destroyed so there was no determination of the cause of the incident or of its attackers.
- A teleworker brought home a laptop containing classified intelligence information. It was stolen during a burglary and never recovered.
- A disgruntled employee of a contractor for BRI disclosed classified documents through the media. He provided the media with, among other things, confidential correspondence between U.S. diplomats and the President that were very revealing.

- Malware had infected all of the computers in several foreign embassies causing public embarrassment, security risks for personnel and financial losses to individuals, businesses and government agencies including foreign entities.

These reports prompted the U.S. Government Accountability Office to conduct a comprehensive review of BRI's information security posture. Using standards and guidance provided by the National Institute of Standards and Technology and other parties, they had the following findings:

Prepare the Risk Assessment Plan

Using the NIST report as your guide, address the following items:
- Purpose of the assessment,
- Scope of the assessment,
- Assumptions and constraints, and
- Selected risk model and analytical approach to be used.

Document your above analysis in the "Interim Risk Assessment Planning Report." (An interim report will be consolidated to a final deliverable in a later step.)

All interim reports should be at least 500 words long and include at least five references for each report. These reports will eventually be presented to management for their review.

Conduct the Assessment

Again, use the NIST report to address the following:
1) Identify threat sources and events (See APPENDIX E)
2) Identify vulnerabilities and predisposing conditions (See APPENDIX F)
3) Determine likelihood of occurrence (APPENDIX G)
4) Determine magnitude of impact (APPENDIX H)
5) Determine risk (See APPENDIX I)

You are free to make assumptions but be sure to state them in your findings.

In determining risk, include the assessment tables reflect BRI's risk levels. Refer to Appendix I. on risk determination in Special Publication 800-30.

Document your analysis from this step in the "Interim Risk Assessment Findings Report. " Be sure to include the final risk evaluations in this report.

Identify Needed Controls and Programs

Research and specify security controls needed to close the security gaps in BRI.
Also, be sure to include a description of the following programs for securing BRI:
- Security Awareness and Training Program (i.e., communications to employees regarding security)
- Privacy Protection Program
- Business Continuity/Disaster Recovery Program
You should justify the need for the agency to invest in your recommendations.
Document your findings and recommendations from this step in the "Interim Security Recommendations Report."

Communicate the Overall Findings and Recommendations

Integrate of your earlier interim reports into a final management report. Be sure to address:
- Summary of the Current Security Situation at BRI (from Step 1)
- Risk Assessment Methodology (from Step 2)
- Risk Assessment Plan (from Step 3)
- Risk Assessment Findings (from Step 4)
- Security Recommendations Report (from Step 5)
- Conclusions

Attachment:- Risk analysis project.rar

Verified Expert

This paper identifies Interim Risk Assessment Planning Report, Interim Risk Assessment Findings Report Interim Security Recommendations Report these three interim reports has been analysed in this section.System security has been analysed and these are identified accordingly. Systems security has been attached in the project content , the attached content has been carefully and thoroughly studied.

Reference no: EM132275408

Questions Cloud

What is your opinion on the outcome : In order to participate fully in this discussion, examine Florida v. Jardines: SCOTUS Blog. Then, reflect on how the appeals process worked in this case.
Explain dual-diagnosis in detail : For this discussion, define and explain dual-diagnosis and how it should be considered separately from substance abuse alone. In your discussion.
What is assembly-line efficiency : What is the cycle time? What is assembly-line efficiency? What is total idle time?
Code processing the image pixels : In what order is the following code processing the image pixels?
Maintaining the it security strategy in organizations : Conduct an IT security risk assessment - You and the team play a key role in defining, implementing and maintaining the IT security strategy in organizations
Drawbacks of defining scope on onset of project plan : What are the benefits and drawbacks of defining a scope on the onset of a project plan?
What is a business continuity plan : 1. What is a business continuity plan, and why is it important? Why and how is it implemented? What is the key purposes of the plan?
Discuss how information from research could be used : Describe the misconception you observed and discuss how information from research could be used to change this misconception about psychological disorders.
Produces cast bronze valves for use in offshore oil platform : Gibson Products produces cast bronze valves for use in offshore oil platforms.

Reviews

len2275408

4/4/2019 11:11:38 PM

Interim Risk Assessment Planning Report Interim Risk Assessment Findings Report Interim Security Recommendations Report These are the deliverable reports I need for Systems Security finding in the attached project content. Please read the attached document very carefully and thoroughly. Make sure these reports are at PhD level. No generalized assumptions and be follow all directions. Please follow every step.

Write a Review

Risk Management Questions & Answers

  A project report on mutual funds

This project report speaks of the core and future aspects of Mutual Funds and the present challenges to cope with.

  Evalaute the theoretical option price

Evalaute the theoretical option price

  Risk and return

Investing in the stock market and Risk-free investment and inflation

  Evaluate the gross profit

Evaluate the gross profit

  Discuss concepts of risk and management

Risk lies at all levels of business activity. There are many different kinds of risks within an management as well as ways to manage risks.

  Determine the average risk premium

Here are stock market & Treasury bill percentage (%) returns between 2006 and 2010: Determine the average risk premium

  Hypothetical healthcare organization ratios

Discuss and explain why one should apply caution when using financial ratios for analyzing a healthcare management's current financial position and future viability.

  Discuss role of risk assessment

The financial information has been dominated currently by stories of financial institutions that have mis-measured risk as part of subprime mortgage crisis.

  Calculate maturity risk premium

The real risk-free rate is 3 percent, & inflation is expected to be 3 percent for the next two years. A 2-year Treasury security yields 6.3 percent.

  Selcting best option for portfolio

Suppose you are planning investing in two stocks to form a portfolio. Assume you do not like risk. Which one of given stock combinations will you select for your portfolio?

  Result of systematic or unsystematic risk

It has been a little over one year since the collapse of Lehman Brothers which was the first major event in the downturn of our stock market & economy.

  Determine risk management

Determine risk management? Discuss the importance of risk management in an organization? How does risk management mitigation create value for an organization?

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd