What types of risks or vulnerabilities could be transferred

Assignment Help Management Information Sys
Reference no: EM131395994

Assignment: Cybersecurity in Business & Industry

Industry Profile Part 1: Acquisition & Procurement Risk in the Cybersecurity Industry

For this paper, you will investigate and then summarize key aspects of risk and risk management for acquisitions or procurements of cybersecurity products and services. The specific questions that your industry profile will address are:

1. What types of risks or vulnerabilities could be transferred from a supplier and/or imposed upon a purchaserofcybersecurity related products and/or services?

2. Are suppliers liable for harm or loss incurred by purchasers of cybersecurity products and services? (That is, does the risk transfer from seller to buyer?)

3. How can governance frameworks be used by both suppliers and purchasers of cybersecurity related products and services to mitigate risks?

First, you will research how operational risk during the manufacturing, development, or service delivery processes can affect the security posture (integrity) of products and services. You will then explore the problem of product liability and/or risk transference from supplier to purchaser as products or services are delivered, installed, and used. You will then examine the role that IT governance frameworks and standards can play in helping purchasers develop and implement risk mitigation strategies to compensate for potential risk transfer by suppliers. Once you have completed your research and analysis, you will summarize your research in a risk profile.

Research

1. Research risks and/or vulnerabilities which could be introduced into a buyer's organization and/or IT operations through acquisition or purchase of cybersecurity products or services. Some suggested resources are:

a. Hardware Security:

i. https://www.brookings.edu/~/media/research/files/papers/2011/5/hardware-cybersecurity/05_hardware_cybersecurity.pdf
ii. https://resources.infosecinstitute.com/hardware-attacks-backdoors-and-electronic-component-qualification/

b. Software Security

i. https://buildsecurityin.us-cert.gov/
ii. https://www.bsimm.com/

c. Data Center Security

i. https://www.datacenterjournal.com/managing-data-center-security/

d. Telecommunications Systems

i. https://www.pwc.com/gx/en/communications/publications/communications-review/assets/cyber-telecom-security.pdf

2. Identify five or more specific sources of operational risks, in a supplier's organization, which could adversely affect the security of cybersecurity products or services. In addition to using information you found under #1, consult the Software Engineering Institute's publication A Taxonomy of Operational Cyber Security Riskshttps://resources.sei.cmu.edu/asset_files/TechnicalNote/2010_004_001_15200.pdf

3. Research the issue of product liability with respect to cybersecurity products and services. What is the current legal environment? Some suggested sources are:

a. https://www.darkreading.com/vulnerabilities---threats/security-product-liability-protections-emerge/d/d-id/1320274

b. https://victorsheymov.com/2015/04/product-liability-the-unique-position-of-the-cybersecurity-industry/

c. https://www.travelers.com/prepare-prevent/protect-your-business/product-services-liability/product-liability-prevention.aspx

4. Research the role of IT Governance standards in helping organizations identify and manage risks arising from the purchase of IT related products and services. Begin by looking at the following:

a. COBIT: AI5 Procure IT Resources
b. ITIL: Supplier Management SD 4
c. ISO/IEC 27002 Section 15: Supplier Relationship Management

i. 15.1 Establish security agreements with suppliers
ii. 15.2 Manage supplier security and service delivery

Write

1. An introduction section which provides a brief overview of the cybersecurity industry as a whole. Why does this industry exist? (Hint: buyers want to procure or acquire cybersecurity related products and services). How does this industry benefit society?Address the sources of demand for cybersecurity products and services. (You may reuse resources and/or narrative from your Case Study #3 assignment.)

2. An operationalrisks overview section in which you provide an overview of sources of operational risks which could affect suppliers of cybersecurity related products and services and, potentially, compromise the security of those products or services. Discuss the potential impact of such compromises upon buyers and the security of their organizations (risk transfer).

3. A product liability section in which you provide a summary of the current legal environment as it pertains to product liability in the cybersecurity industry. Discuss the potential impact upon buyers who suffer harm or loss as a result of purchasing, installing, and/or using cybersecurity products or services.

4. A governance frameworks & standards section in which you discuss the role that standards and governance processes should play in ensuring that acquisitions or purchases of cybersecurity products and services meet the buyer's organization's security requirements (risk mitigation).

5. A summary and conclusions section in which you present a summary of your findings including the reasons why product liability (risk transfer) is a problem that must be addressed by both suppliers and purchasers of cybersecurity related products and services.

Yourfive to eight pagepaper is to be prepared using basic APA formatting (including title page and reference list)and submitted as an MS Word attachment to the Industry Profile Part 1: Acquisition & Procurement Risk entry in your assignments folder. See the sample paper and paper template provided in Course Resources > APA Resources for formatting examples.Consult the grading rubric for specific content and formatting requirements for this assignment.

Reference no: EM131395994

Questions Cloud

Calculate the yield to maturity of loan : 1. According to a website of an installment lender, borrowers in California could be eligible to receive a loan of $2600 and pay back by making fixed monthly payments of $767.96 for nine months. Calculate the yield to maturity of this loan. Answe..
Should network administrators be left to the business unit : Do you think network administrators should have the final say with regard to security, or should it be left to the business unit? Why do you think that?
Will preventing imports create jobs : Which groups of population in the US will benefit from a 10% tariff on Mexican made cars and which groups would lose out? Will preventing imports create jobs? Why or Why not?
Write a conclusion about the effect of the course : At the end of the course, the same test was given again. High scores mean lots of misconceptions. Analyze the data and write a conclusion about the effect of the course on misconceptions.
What types of risks or vulnerabilities could be transferred : CSIA 350- What types of risks or vulnerabilities could be transferred from a supplier and/or imposed upon a purchaserofcybersecurity related products and/or services?
Dollar of additional government spending : According to traditional Keynesian analysis, which has a larger impact on GDP--a dollar of tax cuts or a dollar of additional government spending? Which would usually help to fight a recession more effectively--tax cuts or additional government s..
Martha opportunity cost of lending the money : Martha lends $200 to a friend who promises to return it after a year. Instead of lending it to her friend, Martha could have put the money in a bank where she could have earned an interest rate of 2 percent per annum. Martha's opportunity cost of ..
Shape of contour lines : Draw thecontour lines (in the positive quadrant) for this function for Y = 4, Y = 5,and Y = 10. What do we call the shape of these contour lines? Where doesthe line 20X + 10Z = 200 intersect with the contour lineY = 50?
Assignment choice-income inequality : Select a country in the Asian-Pacific region as a case study for this assignment. Then write a critical essay addressing the following items:

Reviews

Write a Review

Management Information Sys Questions & Answers

  Describe a business that would like to start

Describe  a business that would like to start discuss how you would use global outsourcing to accomplish yourgoals

  Write an introductory statement of the company

Term Paper: Information Technology Strategic Plan, Imagine that a company has recently hired you as a senior business consultant. Write an introductory statement of the company

  Have organizations prepared for the baby boomer exodusshow

have organizations prepared for the baby boomer exodus?show knowledge and information that might be lost to

  Demonstrate the use of conditional and looping structures

The Java application should also meet these technical requirements: The application should have at least one class, in addition to the application's controlling class. The source code must demonstrate the use of conditional and looping structures

  Explain the four components of an information system

In a formal 250 - 500 word essay, describe the four components of an information system. Why is it important to consider each of them when designing and installing an information system

  How they differ based on organizational requirements

Types of networks, how they differ based on organizational requirements, interconnected devices and geographical area served - Identify PROS and CONS

  Using the internet to gain competitive advantageessay 250

using the internet to gain competitive advantageessay 250 words. explain how internet can help a company to achieve a

  Supply-chain risks1 discuss a recent example of an

supply-chain risks1. discuss a recent example of an unknown-unknown risk that proved damaging to a supply chain.

  How will he manage payments and shipping

One difficulty of moving a small business from a traditional retail store to an online store is channel complications. Everything must be reconsidered. For example, how will he communicate with his customers? How will they find product information..

  Question about information systems managementexplain the

question about information systems managementexplain the concept of web services. how will they effect businesses in

  Major copyright issues faced by the entertainment

major copyright issues faced by the entertainment industrywhat are the major copyright issues faced by the

  What was the implied stock out cost

Based on Martin Quinn's estimate of other stock out costs, how many servings should the chef prepare?- What was the implied stock out cost?

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd