What risk treatment strategies would you recommend

Assignment Help Other Subject
Reference no: EM132550122

Question Q1:
a) Explain, what main functions under an InfoSec program would you recommend a smaller organisation with three full time staff and two or three part-time roles from other parts of the business.? Specify for InfoSec department and other departments. Specify the functions that would be performed by the different departments and indicate if any functions could be outsourced. Justify your allocation of functions.

b) The New Zealand Privacy Act 1993 focuses on the storage and security of personal information. It requires agencies to ensure that the personal information is protected by reasonable security safeguards. Discuss how the New Zealand COVID tracing app adheres to all the relevant principles of the New Zealand Privacy Act and ensures that there will be no personal data compromise? information in consideration of each of the specific principles of New Zealand Privacy Act?.

Question Q2:
a) Consider a data classification scheme that contains the categories "confidential", "sensitive", and "unclassified" . Define these categories first, and then apply them to categorise five information assets contained in your personal computer. Explain the reason for the classification of each of the assets.

b) Consider a home office that comprises a laptop running the latest Windows OS, a monitor, a wireless keyboard and a wireless mouse ( one dongle), a backup device (external hard disk), an external DVD drive, and a fibre optic based Internet connection managed by an ISP that connects the home office Wi-Fi to the Internet. Perform a TVA (threat -vulnerability-asset) assessment of the home office IT infrastructure based on your general knowledge about the hardware described. Include all assets and identify at least three threats (see Table 6-8 on page 341).

Question Q3:
a) What risk treatment strategies would you recommend to banking industry as part of their information security program? Explain these in the context of the various business processes and resources.
b) Consider the case of ABC Software Company which is facing a number of major information security threats (as listed in the table below). The information security team has estimated the cost per incident which the company will bear if the threat is materialised. Calculate the Single Loss Expectancy (SLE), Annualized Rate of Occurrence (ARO), and Annualized Loss Expectancy (ALE) for each threat.

 

ABC Software Cost per             Frequency of             SLE ARO ALE

Company major incident         Occurrence

threats

Programmer      $4,500.00     2 per week

mistakes

Flood            $250,000.00     1 per 10 years

Virus, Worms, $1,500.00        1 per week

Trojan

Denial-of-                   $6,500.00     1 per quarter

service attacks

Theft of            $6,000.00     1 per 6 months

information

Question Q4:
a) Consider a tertiary education organization (e.g., a university). Consider applying mandatory access controls vs non-discretionary access controls with respect to student records. (Assume that student records include these four categories: (i) personal details,( H) external documents supplied by the student, (Hi) records about study progress, e.g., enrolment and grades , and (iv) internal documents generated administratively such as letters sent to the student). Which approach would you recommend, mandatory access controls or nondiscretionary access controls? Justify your recommendation, referring specifically to the four categories above.

b) Why is it a good security practice to collect and report near-miss event in which major incidents were only narrowly averted (such as spam messages that were not filtered out ) need to be collected and reported? Explain your answer providing five examples of hypothetical near-miss events. and what weaknesses they may indicate.

Reference no: EM132550122

Questions Cloud

What does the price-earnings ratio show : What does the price/earnings (P/E) ratio show? If one firm's P/E ratio is lower than that of another, what are some factors that might explain the difference
Network security-what is the purpose of https : What is the difference between a TLS connection and a TLS session? What is the purpose of HTTPS? What services are provided by the TLS Record Protocol?
Case - Sales Type versus Direct Financing Leases : Case - Sales Type versus Direct Financing Leases. Describe how a capital lease would be accounted for by the lessee both at the inception of the lease
Explain which systems you feel are mission critical : Explain in your own words why you believe planning is important. explain which systems you feel are mission critical.
What risk treatment strategies would you recommend : what main functions under an InfoSec program would you recommend a smaller organisation with three full time staff and two or three part-time roles from other
Duties of digital forensic examiner : As a part of the duties of a digital forensic examiner, creating an investigation plan is a standard practice.
Student threatening to commit suicide : You get a call from a high school student named Marco who claims he has just received an email from another student threatening to commit suicide
Good job of illustrating the worst case : You think do a particularly good job of illustrating (1) the worst case scenario and (2) the best case scenario when it comes to cybersecurity
Conduct in-depth investigation-evolution and trends : Which you would like to conduct an in-depth investigation. Managerial issues of a networked organization. Emerging enterprise network applications

Reviews

len2550122

6/19/2020 9:22:35 PM

I just want you to answer this questions within 5 hours I've to submit it after 5 hours and the book we are using is (Management of information security)

Write a Review

Other Subject Questions & Answers

  Cross-cultural opportunities and conflicts in canada

Short Paper on Cross-cultural Opportunities and Conflicts in Canada.

  Sociology theory questions

Sociology are very fundamental in nature. Role strain and role constraint speak about the duties and responsibilities of the roles of people in society or in a group. A short theory about Darwin and Moths is also answered.

  A book review on unfaithful angels

This review will help the reader understand the social work profession through different concepts giving the glimpse of why the social work profession might have drifted away from its original purpose of serving the poor.

  Disorder paper: schizophrenia

Schizophrenia does not really have just one single cause. It is a possibility that this disorder could be inherited but not all doctors are sure.

  Individual assignment: two models handout and rubric

Individual Assignment : Two Models Handout and Rubric,    This paper will allow you to understand and evaluate two vastly different organizational models and to effectively communicate their differences.

  Developing strategic intent for toyota

The following report includes the description about the organization, its strategies, industry analysis in which it operates and its position in the industry.

  Gasoline powered passenger vehicles

In this study, we examine how gasoline price volatility and income of the consumers impacts consumer's demand for gasoline.

  An aspect of poverty in canada

Economics thesis undergrad 4th year paper to write. it should be about 22 pages in length, literature review, economic analysis and then data or cost benefit analysis.

  Ngn customer satisfaction qos indicator for 3g services

The paper aims to highlight the global trends in countries and regions where 3G has already been introduced and propose an implementation plan to the telecom operators of developing countries.

  Prepare a power point presentation

Prepare the power point presentation for the case: Santa Fe Independent School District

  Information literacy is important in this environment

Information literacy is critically important in this contemporary environment

  Associative property of multiplication

Write a definition for associative property of multiplication.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd