Explain effective incident management system, Risk Management

Assignment Help:

Question 1:

(a) Explain what is meant by the term „incident handling? in the context of information security.

(b) Describe the main features of an effective incident management system.

(c) Explain the main goals of a Business Impact Assessment for management and its role in incident management.

(d) Explain the main phases of the OCTAVE method for risk assessment and the key success factors for its implementation.

Question 2:

You have just been appointed as Security Consultant, reporting directly to the Chief Executive Officer in a major bookstore which in addition to its main store also operates an interactive website where orders can be placed online by customers as well as accepting credit card payments online. Your role is to advise management on what needs to be done by the company to be compliant with section 6.6 of the Payment Card Industry Data Security Standard. Your answer should state the security requirements for section 6.6 of the PCI DSS and focus on the process and options that management need to consider in order to secure web-based applications to be compliant with section 6.6.


Related Discussions:- Explain effective incident management system

Leverage, evaluate the importance of leverage in financial management of a...

evaluate the importance of leverage in financial management of a small company

Homework 2, I have already sent my homework yesterday, please respond: from...

I have already sent my homework yesterday, please respond: from email:

What is business risk - non-systematic risk, What is Business Risk - Non-Sy...

What is Business Risk - Non-Systematic Risk Risk of doing business in a particular industry or environment is known as business risk. For instance, as one of the largest steel

Risk management and financial institutions, On September 25,2008 a portfoli...

On September 25,2008 a portfolio worth $10 million consisting of investments in four stock indices: DJIA, FTSE 100, CAC 40 and NIKKEI 225. The value of the investment in each index

What is avoidance of risk, Q. What is Avoidance of Risk? A business fir...

Q. What is Avoidance of Risk? A business firm can avoid risk by not accepting any assignment or any transaction which involves any type of risk whatsoever. This will naturally

Contingency plan, Part 1: Contingency plan Create contingency plans for the...

Part 1: Contingency plan Create contingency plans for the following scenarios: > One of your highly qualified consultants has given three months notice and is planning to move to a

Register sample format and example risk, Using the above information, and a...

Using the above information, and any other information (state assumptions), create the start of a risk register for the project, using the Risk Register Sample below as a guide. Id

Requirement of relevant control of iso, Question: For each of the situa...

Question: For each of the situations below:- (a) Mention most relevant clause of ISO 27001:2005 (b) Whether the practice followed in the organization is appropriate and i

Disaster recovery plan, Devise a disaster recovery plan • Business Impact A...

Devise a disaster recovery plan • Business Impact Analysis • Treatment Strategies: o Risk Avoidance o Risk Reduction o Risk Transfer o Risk Retention • Ingredients of a disaster re

Write Your Message!

Captcha
Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd