Define the scope and boundaries for the risk assessment


Assignment:

Purpose

Risk management is an important process for all organizations. This is particularly true in information systems, which provides critical support for organizational missions. The heart of risk management is a formal risk management plan. This project allows you to fulfill the role of an employee participating in the risk management process in a specific business situation.

Learning Objectives and Outcomes

You will gain an overall understanding of risk management, its importance, and critical processes required when developing a formal risk management plan for an organization.

Required Source Information and Tools

Web References: Links to web references in this document and related materials are subject to change without prior notice. These links were last verified on October 8, 2020.

The following tools and resources will be needed to complete this project:

Course textbook

Internet access

Suggested resources:

o NIST RMF:

o NIST risk assessment guidance:

o NIST contingency planning guidance:

o Business Impact Analysis,

o Business Continuity Plan (Ready.gov):

Scenario

You are an IT security intern working for Health Network, Inc. (Health Network), a fictitious health services organization headquartered in Minneapolis, Minnesota. Health Network has over 600 employees throughout the organization and generates $500 million USD in annual revenue. The company has two additional locations in Portland, Oregon and Arlington, Virginia, which support a mix of corporate operations. Each corporate facility is located near a co-location data center, where production systems are located and managed by third-party data center hosting vendors.

Deliverable

This project is divided into several parts, each with a deliverable. The first four parts are drafts. These documents should resemble business reports in that they are organized by headings, include source citations (if any), be readable, and be free from typos and grammatical errors. However, they are not final, polished reports.

Project Part 2: Risk Assessment Plan

After creating an initial draft of the risk management plan, the next step is to create a draft of the risk assessment plan. For this part of the project:

  1. Research risk assessment approaches.
  2. Create an outline for a basic qualitative risk assessment plan.
  3. Write an introduction to the plan explaining its purpose and importance.
  4. Define the scope and boundaries for the risk assessment.
  5. Identify data center assets and activities to be assessed.
  6. Identify relevant threats and vulnerabilities. Include those listed in the scenario and add to the list if needed.
  7. Identify relevant types of controls to be assessed.
  8. Identify the key roles and responsibilities of individuals and departments within the organization as they pertain to risk assessments.
  9. Develop a proposed schedule for the risk assessment process.
  10. Complete the draft risk assessment plan detailing the information above. Risk assessment plans often include tables, but you choose the best format to present the material. Format the bulk of the plan similar to a professional business report and cite any sources you used.

Submission Requirements

Format: Microsoft Word (or compatible)

Font: Arial, size 12, double-space

Citation style: APA Format

Estimated length: 4 to 6 pages

Solution Preview :

Prepared by a verified Expert
Risk Management: Define the scope and boundaries for the risk assessment
Reference No:- TGS03207604

Now Priced at $100 (50% Discount)

Recommended (92%)

Rated (4.4/5)