Reference no: EM131977268
Determining Jurisdiction
John Miller is the information security and privacy officer of a local county-owned teaching hospital. He is new to his position and began his work by evaluating the existing security and privacy controls that are in place in the institution.
He is also new to information security, having only recently graduated with a BS in information security with professional experience as an active-directory administrator for two years.
This work with active directory created his interest in pursuing a position in the field of security. Because he has most experience in the area of account management, user creation and management, groups, roles and group policy, these are the areas where he began his work.
He found literally hundreds of idle accounts indicating that users are created but are not properly discontinued when medical students, nursing students, and other employees move on and no longer need access to the data collected and stored by the hospital.
This discovery inspired him to begin digging into other aspects of the security controls, and he found evidence of malware on the servers that house the data collected and stored for use by the hospitals clinical systems.
His next discovery was the most alarming. The objective of the malware that had deeply infested the hospital systems was to package and transmit all available data to a remote host located in North Korea.
John is clearly in over his head at this point and needs to act quickly to resolve this situation and stop the flow of personally identifiable health information to an unauthorized third party.
Use the study materials and any additional research needed to fill in knowledge gaps. Then discuss the following:
What primary laws, regulations, or statutes have been violated by this lack of attention to controls, leading to this serious breach of security?
What channels of communication should John enlist to assist him in resolving this matter, and in what order should those communication sources be contacted?
What tools and any supporting resources are available to John to determine the breadth of the breach and the mitigations available to secure those assets?
How much would you have in one year
: A friend asks to borrow $55 from you and in return will pay you $58 $58 in one year. If your bank is offering a 5.7% interest rate on deposits and loans.
|
What is the speed of the wire when pulled
: What is the speed of the wire when pulled with 1.0 N? -answer units m/s What is the strength of the magnetic field? -answer units in T
|
Baseball with a de broglie wavelength
: What is the speed of a 204 g baseball with a de Broglie wavelength of 0.210 nm?
|
What would the annual yield to maturity be on the bond
: Fresh Fruit, Inc. has a $1,000 par value bond that is currently selling for $1,227. It has an annual coupon rate of 12.86 percent, paid semiannually.
|
What channels of communication should john enlist to assist
: What primary laws, regulations, or statutes have been violated by this lack of attention to controls, leading to this serious breach of security?
|
What would the annual yield to maturity be on the bond
: Fresh Fruit, Inc. has a $1,000 par value bond that is currently selling for $1,126. It has an annual coupon rate of 15%, paid semiannually, and has 17 years.
|
Write a measurable IEP goal for gabriella
: Benchmark - Language Disabilities and Assistive Technology Unit Plan - Write a measurable IEP goal for Gabriella that includes the use of augmentative
|
How much money could you borrow today
: A friend asks to borrow $50 from you and in return will pay you $53 in one year. If your bank is offering a 5.8% intrest rate on deposits and loans.
|
Who are your organizations competitors
: How does your organization gather information to be on the forefront of information technology development? What type of research facilities exist?
|