SlideShare a Scribd company logo
1 of 11
COURSE PROJECT 2
Operating System and Application Security Strategy (Unit4)
Operating System Security Vulnerabilities (list 2 OS)Operating
System 1Operating System 2
Antimalware Recommendation
(should be specific to your target company and its environment)
Intrusion Detection System Recommendation
(should be specific to your target company and its environment)
Application SecurityWeb-based Infrastructure
RecommendationsAS Recommendation 1AS Recommendation
2Database Infrastructure RecommendationsDB Recommendation
1
DB Recommendation 2
Policy Recommendations (See Course Project on Pg. 8 for
unit)Policy Recommendation1Policy Recommendation 2
Project: Risk Management Plan
Purpose
This project provides an opportunity to apply the competencies
gained in the lessons of this course to develop a risk
management plan for a fictitious organization to replace its
outdated plan.
Learning Objectives and Outcomes
You will gain an overall understanding of risk management, its
importance, and critical processes required when developing a
formal risk management plan for an organization.
Required Source Information and Tools
Web References: Links to Web references in this document and
related materials are subject to change without prior notice.
These links were last verified on April 19, 2015.
The following tools and resources that will be needed to
complete this project:
· Course textbook
· Internet access for research
Deliverables
As discussed in this course, risk management is an important
process for all organizations. This is particularly true in
information systems, which provides critical support for
organizational missions. The heart of risk management is a
formal risk management plan. The project activities described in
this document allow you to fulfill the role of an employee
participating in the risk management process in a specific
business situation.
The project is structured as follows:
Project Part
Deliverable
Project Part
Risk Management Plan – Due 4/17
Submission Requirements
All project submissions should follow this format:
· Format: Microsoft Word or compatible
· Font: Arial, 10-point, double-space
· Citation Style: Your school’s preferred style guide
Scenario
You are an information technology (IT) intern working for
Health Network, Inc. (Health Network), a fictitious health
services organization headquartered in Minneapolis, Minnesota.
Health Network has over 600 employees throughout the
organization and generates $500 million USD in annual
revenue. The company has two additional locations in Portland,
Oregon and Arlington, Virginia, which support a mix of
corporate operations. Each corporate facility is located near a
co-location data center, where production systems are located
and managed by third-party data center hosting vendors.
Company Products
Health Network has three main products: HNetExchange,
HNetPay, and HNetConnect.
HNetExchange is the primary source of revenue for the
company. The service handles secure electronic medical
messages that originate from its customers, such as large
hospitals, which are then routed to receiving customers such as
clinics.
HNetPay is a Web portal used by many of the company’s
HNetExchange customers to support the management of secure
payments and billing. The HNetPay Web portal, hosted at
Health Network production sites, accepts various forms of
payments and interacts with credit-card processing
organizations much like a Web commerce shopping cart.
HNetConnect is an online directory that lists doctors, clinics,
and other medical facilities to allow Health Network customers
to find the right type of care at the right locations. It contains
doctors’ personal information, work addresses, medical
certifications, and types of services that the doctors and clinics
offer. Doctors are given credentials and are able to update the
information in their profile. Health Network customers, which
are the hospitals and clinics, connect to all three of the
company’s products using HTTPS connections. Doctors and
potential patients are able to make payments and update their
profiles using Internet-accessible HTTPS Web sites.
NOTE: Any discussion of products not a part of this scenario,
such as health insurance products, will result in an automatic
50% reduction in points. Your paper is not a research paper on
risk management – it is a risk management plan to a very
specific situation and must relate to the scenario, above.
Information Technology Infrastructure Overview
Health Network operates in three production data centers that
provide high availability across the company’s products. The
data centers host about 1,000 production servers, and Health
Network maintains 650 corporate laptops and company-issued
mobile devices for its employees.
Threats Identified
Upon review of the current risk management plan, the following
threats were identified:
· Loss of company data due to hardware being removed from
production systems
· Loss of company information on lost or stolen company-
owned assets, such as mobile devices and laptops
· Loss of customers due to production outages caused by various
events, such as natural disasters, change management, unstable
software, and so on
· Internet threats due to company products being accessible on
the Internet
· Insider threats
· Changes in regulatory landscape that may impact operations
Management Request
Senior management at Health Network has determined that the
existing risk management plan for the organization is out of
date and a new risk management plan must be developed.
Because of the importance of risk management to the
organization, senior management is committed to and supportive
of the project to develop a new plan. You have been assigned to
develop this new plan.
Additional threats other than those described previously may be
discovered when re-evaluating the current threat landscape
during the risk assessment phase.
The budget for this project has not been defined due to senior
management’s desire to react to any and all material risks that
are identified within the new plan. Given the company’s annual
revenue, reasonable expectations can be determined.
Project Part 1
Project Part 1 Task 1: Risk Management Plan
For the first part of the assigned project, you must create an
initial draft of the final risk management plan. To do so, you
must:
You Risk Management Plan will contain the following sections:
1. A section titled Introduction discussing the purpose of the
plan. You must include details from the scenario, above,
describing the environment. 10 points.
2. A section titled Scope discussing the scope of the plan. 10
points
3. A section, titled Compliance Laws and Regulations. Using
the information in the scenario provided above, discuss
regulations and laws with which Health Network must comply.
30 points
4. A section, titled Roles and Responsibilities, that will discuss
the different individuals and departments who will be
responsible for risk management within the organization (this
was presented in your textbook). 20 points
5. A section, titled Risk Mitigation Plan, that discusses the
threats identified in the scenario and your proposed mitigations,
as well as any new threats.30 points.
Write an initial draft of the risk management plan as detailed in
the instructions above. Your plan should be made using a
standard word processor format compatible with Microsoft
Word.
Evaluation Criteria and Rubrics
· Did the student demonstrate an understanding of the
competencies covered in the course thus far?
· Did the student include all important components of a risk
management plan in the outline?
· Did the student demonstrate good research, reasoning, and
decision-making skills in identifying key components and
compliance laws and regulations?
· Did the student create a professional, well-developed draft
with proper grammar, spelling, and punctuation?
© 2015 by Jones & Bartlett Learning, LLC, an Ascend Learning
Company. All rights reserved.
www.jblearning.com Page 3
Project: Risk Management Plan
© 201
5
by Jones & Bartlett Learning, LLC, an Ascend Learning
Company
. All rights reserved.
www.jblearning.com
Page
1
Purpose
This project provides an
opportunity
to apply the competencies gained in
the
lesson
s
of this course to
develop a risk management plan for a
fictitious organization
to replace its outdated plan
.
Learning Objectives and Outcomes
You will
gain an overall understanding of risk management, its
importance, and critical processes
required when developing a formal risk m
anagemen
t p
lan for an organization.
Required Source
Information and Tools
Web References:
Links to Web references in this document and related materials
are subject to change
without prior notice. These links were last verified on
April
19
, 2015
.
The following tools and resources
that
will be needed to com
plete this project:
§
Course textbook
§
Internet access for research
Deliverables
As discussed in this course, risk management is an important
process for all organizations. This is
particularly true in information systems, which provides critical
support for
organizational missions. The
heart of risk management is a formal risk management plan.
Th
e
project
activit
ies described in this
document
allow you to fulfill the role of an employee participating in the
risk management process in a
specific business situa
tion.
The project is
structured
as follows:
Project Part
Deliverable
Project Part
Risk Management Plan
–
Due
4/17
Submission Requirements
All project submissions should follow this format:
§
Format: Microsoft Word
or compatible
§
Font
: Arial, 1
0
-
point
,
d
ouble
-
s
pace
§
Citation Style: Your school’s preferred style guide
Scenario
Project: Risk Management Plan
© 2015 by Jones & Bartlett Learning, LLC, an Ascend Learning
Company. All rights reserved.
www.jblearning.com Page 1
Purpose
This project provides an opportunity to apply the competencies
gained in the lessons of this course to
develop a risk management plan for a fictitious organization to
replace its outdated plan.
Learning Objectives and Outcomes
You will gain an overall understanding of risk management, its
importance, and critical processes
required when developing a formal risk management plan for an
organization.
Required Source Information and Tools
Web References: Links to Web references in this document and
related materials are subject to change
without prior notice. These links were last verified on April 19,
2015.
The following tools and resources that will be needed to
complete this project:
Deliverables
As discussed in this course, risk management is an important
process for all organizations. This is
particularly true in information systems, which provides critical
support for organizational missions. The
heart of risk management is a formal risk management plan. The
project activities described in this
document allow you to fulfill the role of an employee
participating in the risk management process in a
specific business situation.
The project is structured as follows:
Project Part Deliverable
Project Part Risk Management Plan – Due 4/17
Submission Requirements
All project submissions should follow this format:
-point, double-space
Scenario

More Related Content

Similar to COURSE PROJECT2Operating System and Application Security Str.docx

Project Risk Management Plan © 2015 by Jones & Bartl.docx
Project Risk Management Plan © 2015 by Jones & Bartl.docxProject Risk Management Plan © 2015 by Jones & Bartl.docx
Project Risk Management Plan © 2015 by Jones & Bartl.docxAASTHA76
 
The project is structured as follows Project Part Deliverable P.docx
The project is structured as follows Project Part Deliverable P.docxThe project is structured as follows Project Part Deliverable P.docx
The project is structured as follows Project Part Deliverable P.docxoscars29
 
Project Risk Management Plan © 2015 by Jones & Bartl.docx
 Project Risk Management Plan © 2015 by Jones & Bartl.docx Project Risk Management Plan © 2015 by Jones & Bartl.docx
Project Risk Management Plan © 2015 by Jones & Bartl.docxgertrudebellgrove
 
Project Risk Management Plan © 2015 by Jones & Bartl.docx
 Project Risk Management Plan © 2015 by Jones & Bartl.docx Project Risk Management Plan © 2015 by Jones & Bartl.docx
Project Risk Management Plan © 2015 by Jones & Bartl.docxaryan532920
 
Submission Requirementsproject submissions should follow th.docx
Submission Requirementsproject submissions should follow th.docxSubmission Requirementsproject submissions should follow th.docx
Submission Requirementsproject submissions should follow th.docxdavid4611
 
You are an information technology (IT) intern working for Health N.docx
You are an information technology (IT) intern working for Health N.docxYou are an information technology (IT) intern working for Health N.docx
You are an information technology (IT) intern working for Health N.docxavaforman16457
 
You are an information technology (IT) intern working for Health.docx
You are an information technology (IT) intern working for Health.docxYou are an information technology (IT) intern working for Health.docx
You are an information technology (IT) intern working for Health.docxavaforman16457
 
CMIS 320 Project 1 Write a justification paper, of at leas
CMIS 320 Project 1 Write a justification paper, of at leasCMIS 320 Project 1 Write a justification paper, of at leas
CMIS 320 Project 1 Write a justification paper, of at leasWilheminaRossi174
 
Is a 1750 words essay. U have to read the book to write the essay .docx
Is a 1750 words essay. U have to read the book to write the essay .docxIs a 1750 words essay. U have to read the book to write the essay .docx
Is a 1750 words essay. U have to read the book to write the essay .docxchristiandean12115
 
Running Head EXECUTIVE SUMMARY6Executive SummaryS.docx
Running Head EXECUTIVE SUMMARY6Executive SummaryS.docxRunning Head EXECUTIVE SUMMARY6Executive SummaryS.docx
Running Head EXECUTIVE SUMMARY6Executive SummaryS.docxcowinhelen
 
Project 1Create an application that displays payroll informatio.docx
Project 1Create an application that displays payroll informatio.docxProject 1Create an application that displays payroll informatio.docx
Project 1Create an application that displays payroll informatio.docxbriancrawford30935
 
This Discussion offers you the opportunity to apply return on in.docx
This Discussion offers you the opportunity to apply return on in.docxThis Discussion offers you the opportunity to apply return on in.docx
This Discussion offers you the opportunity to apply return on in.docxgasciognecaren
 
IT 549 Final Project Guidelines and Rubric Overview .docx
IT 549 Final Project Guidelines and Rubric  Overview .docxIT 549 Final Project Guidelines and Rubric  Overview .docx
IT 549 Final Project Guidelines and Rubric Overview .docxchristiandean12115
 
Term Paper Managing an IT Infrastructure AuditDue Week 10 a.docx
Term Paper Managing an IT Infrastructure AuditDue Week 10 a.docxTerm Paper Managing an IT Infrastructure AuditDue Week 10 a.docx
Term Paper Managing an IT Infrastructure AuditDue Week 10 a.docxmanningchassidy
 
erm Paper Managing an IT Infrastructure AuditDue Week 10 and wo
erm Paper Managing an IT Infrastructure AuditDue Week 10 and woerm Paper Managing an IT Infrastructure AuditDue Week 10 and wo
erm Paper Managing an IT Infrastructure AuditDue Week 10 and woeleanorabarrington
 
1Trends That Need A Closer LookAttention deficit hyper.docx
1Trends That Need A Closer LookAttention deficit hyper.docx1Trends That Need A Closer LookAttention deficit hyper.docx
1Trends That Need A Closer LookAttention deficit hyper.docxvickeryr87
 
ISE 620 Final Project Guidelines and Rubric Overview .docx
ISE 620 Final Project Guidelines and Rubric  Overview .docxISE 620 Final Project Guidelines and Rubric  Overview .docx
ISE 620 Final Project Guidelines and Rubric Overview .docxchristiandean12115
 
Managing-Data-Protection-and-Cybersecurity-Audit-s-Role_joa_Eng_0116
Managing-Data-Protection-and-Cybersecurity-Audit-s-Role_joa_Eng_0116Managing-Data-Protection-and-Cybersecurity-Audit-s-Role_joa_Eng_0116
Managing-Data-Protection-and-Cybersecurity-Audit-s-Role_joa_Eng_0116Mohammed J. Khan
 
Cis 558 Exceptional Education-snaptutorial.com
Cis 558 Exceptional Education-snaptutorial.comCis 558 Exceptional Education-snaptutorial.com
Cis 558 Exceptional Education-snaptutorial.comrobertleses9
 
CIS 558 Enhance teaching / snaptutorial.com
CIS 558 Enhance teaching / snaptutorial.comCIS 558 Enhance teaching / snaptutorial.com
CIS 558 Enhance teaching / snaptutorial.comdonaldzs56
 

Similar to COURSE PROJECT2Operating System and Application Security Str.docx (20)

Project Risk Management Plan © 2015 by Jones & Bartl.docx
Project Risk Management Plan © 2015 by Jones & Bartl.docxProject Risk Management Plan © 2015 by Jones & Bartl.docx
Project Risk Management Plan © 2015 by Jones & Bartl.docx
 
The project is structured as follows Project Part Deliverable P.docx
The project is structured as follows Project Part Deliverable P.docxThe project is structured as follows Project Part Deliverable P.docx
The project is structured as follows Project Part Deliverable P.docx
 
Project Risk Management Plan © 2015 by Jones & Bartl.docx
 Project Risk Management Plan © 2015 by Jones & Bartl.docx Project Risk Management Plan © 2015 by Jones & Bartl.docx
Project Risk Management Plan © 2015 by Jones & Bartl.docx
 
Project Risk Management Plan © 2015 by Jones & Bartl.docx
 Project Risk Management Plan © 2015 by Jones & Bartl.docx Project Risk Management Plan © 2015 by Jones & Bartl.docx
Project Risk Management Plan © 2015 by Jones & Bartl.docx
 
Submission Requirementsproject submissions should follow th.docx
Submission Requirementsproject submissions should follow th.docxSubmission Requirementsproject submissions should follow th.docx
Submission Requirementsproject submissions should follow th.docx
 
You are an information technology (IT) intern working for Health N.docx
You are an information technology (IT) intern working for Health N.docxYou are an information technology (IT) intern working for Health N.docx
You are an information technology (IT) intern working for Health N.docx
 
You are an information technology (IT) intern working for Health.docx
You are an information technology (IT) intern working for Health.docxYou are an information technology (IT) intern working for Health.docx
You are an information technology (IT) intern working for Health.docx
 
CMIS 320 Project 1 Write a justification paper, of at leas
CMIS 320 Project 1 Write a justification paper, of at leasCMIS 320 Project 1 Write a justification paper, of at leas
CMIS 320 Project 1 Write a justification paper, of at leas
 
Is a 1750 words essay. U have to read the book to write the essay .docx
Is a 1750 words essay. U have to read the book to write the essay .docxIs a 1750 words essay. U have to read the book to write the essay .docx
Is a 1750 words essay. U have to read the book to write the essay .docx
 
Running Head EXECUTIVE SUMMARY6Executive SummaryS.docx
Running Head EXECUTIVE SUMMARY6Executive SummaryS.docxRunning Head EXECUTIVE SUMMARY6Executive SummaryS.docx
Running Head EXECUTIVE SUMMARY6Executive SummaryS.docx
 
Project 1Create an application that displays payroll informatio.docx
Project 1Create an application that displays payroll informatio.docxProject 1Create an application that displays payroll informatio.docx
Project 1Create an application that displays payroll informatio.docx
 
This Discussion offers you the opportunity to apply return on in.docx
This Discussion offers you the opportunity to apply return on in.docxThis Discussion offers you the opportunity to apply return on in.docx
This Discussion offers you the opportunity to apply return on in.docx
 
IT 549 Final Project Guidelines and Rubric Overview .docx
IT 549 Final Project Guidelines and Rubric  Overview .docxIT 549 Final Project Guidelines and Rubric  Overview .docx
IT 549 Final Project Guidelines and Rubric Overview .docx
 
Term Paper Managing an IT Infrastructure AuditDue Week 10 a.docx
Term Paper Managing an IT Infrastructure AuditDue Week 10 a.docxTerm Paper Managing an IT Infrastructure AuditDue Week 10 a.docx
Term Paper Managing an IT Infrastructure AuditDue Week 10 a.docx
 
erm Paper Managing an IT Infrastructure AuditDue Week 10 and wo
erm Paper Managing an IT Infrastructure AuditDue Week 10 and woerm Paper Managing an IT Infrastructure AuditDue Week 10 and wo
erm Paper Managing an IT Infrastructure AuditDue Week 10 and wo
 
1Trends That Need A Closer LookAttention deficit hyper.docx
1Trends That Need A Closer LookAttention deficit hyper.docx1Trends That Need A Closer LookAttention deficit hyper.docx
1Trends That Need A Closer LookAttention deficit hyper.docx
 
ISE 620 Final Project Guidelines and Rubric Overview .docx
ISE 620 Final Project Guidelines and Rubric  Overview .docxISE 620 Final Project Guidelines and Rubric  Overview .docx
ISE 620 Final Project Guidelines and Rubric Overview .docx
 
Managing-Data-Protection-and-Cybersecurity-Audit-s-Role_joa_Eng_0116
Managing-Data-Protection-and-Cybersecurity-Audit-s-Role_joa_Eng_0116Managing-Data-Protection-and-Cybersecurity-Audit-s-Role_joa_Eng_0116
Managing-Data-Protection-and-Cybersecurity-Audit-s-Role_joa_Eng_0116
 
Cis 558 Exceptional Education-snaptutorial.com
Cis 558 Exceptional Education-snaptutorial.comCis 558 Exceptional Education-snaptutorial.com
Cis 558 Exceptional Education-snaptutorial.com
 
CIS 558 Enhance teaching / snaptutorial.com
CIS 558 Enhance teaching / snaptutorial.comCIS 558 Enhance teaching / snaptutorial.com
CIS 558 Enhance teaching / snaptutorial.com
 

More from marilucorr

Cover LetterOne aspect of strategic planning is to develop a str.docx
Cover LetterOne aspect of strategic planning is to develop a str.docxCover LetterOne aspect of strategic planning is to develop a str.docx
Cover LetterOne aspect of strategic planning is to develop a str.docxmarilucorr
 
Cover Letter, Resume, and Portfolio Toussaint Casimir.docx
Cover Letter, Resume, and Portfolio Toussaint Casimir.docxCover Letter, Resume, and Portfolio Toussaint Casimir.docx
Cover Letter, Resume, and Portfolio Toussaint Casimir.docxmarilucorr
 
Cover Executive Summary (mention organization, key ‘out-take.docx
Cover Executive Summary (mention organization, key ‘out-take.docxCover Executive Summary (mention organization, key ‘out-take.docx
Cover Executive Summary (mention organization, key ‘out-take.docxmarilucorr
 
couse name Enterprise risk management  From your research, dis.docx
couse name  Enterprise risk management  From your research, dis.docxcouse name  Enterprise risk management  From your research, dis.docx
couse name Enterprise risk management  From your research, dis.docxmarilucorr
 
Courts have reasoned that hospitals have a duty to reserve their b.docx
Courts have reasoned that hospitals have a duty to reserve their b.docxCourts have reasoned that hospitals have a duty to reserve their b.docx
Courts have reasoned that hospitals have a duty to reserve their b.docxmarilucorr
 
Court Operations and Sentencing GuidelinesPeriodically, se.docx
Court Operations and Sentencing GuidelinesPeriodically, se.docxCourt Operations and Sentencing GuidelinesPeriodically, se.docx
Court Operations and Sentencing GuidelinesPeriodically, se.docxmarilucorr
 
Course Competencies Learning ObjectivesCourse Learning Objectiv.docx
Course Competencies Learning ObjectivesCourse Learning Objectiv.docxCourse Competencies Learning ObjectivesCourse Learning Objectiv.docx
Course Competencies Learning ObjectivesCourse Learning Objectiv.docxmarilucorr
 
Coursework 2 – Presentation Report The aim of this 1000-word r.docx
Coursework 2 – Presentation Report  The aim of this 1000-word r.docxCoursework 2 – Presentation Report  The aim of this 1000-word r.docx
Coursework 2 – Presentation Report The aim of this 1000-word r.docxmarilucorr
 
CourseOverview-MarketingChannelConceptsLecture1.docx
CourseOverview-MarketingChannelConceptsLecture1.docxCourseOverview-MarketingChannelConceptsLecture1.docx
CourseOverview-MarketingChannelConceptsLecture1.docxmarilucorr
 
course-text-booksKeri E. Pearlson_ Carol S. Saunders - Managing.docx
course-text-booksKeri E. Pearlson_ Carol S. Saunders - Managing.docxcourse-text-booksKeri E. Pearlson_ Carol S. Saunders - Managing.docx
course-text-booksKeri E. Pearlson_ Carol S. Saunders - Managing.docxmarilucorr
 
COURSE  InfoTech in a Global Economy Do you feel that countri.docx
COURSE  InfoTech in a Global Economy Do you feel that countri.docxCOURSE  InfoTech in a Global Economy Do you feel that countri.docx
COURSE  InfoTech in a Global Economy Do you feel that countri.docxmarilucorr
 
Course Themes Guide The English 112 course will focus o.docx
Course Themes Guide  The English 112 course will focus o.docxCourse Themes Guide  The English 112 course will focus o.docx
Course Themes Guide The English 112 course will focus o.docxmarilucorr
 
Course SyllabusPrerequisitesThere are no prerequisites for PHI20.docx
Course SyllabusPrerequisitesThere are no prerequisites for PHI20.docxCourse SyllabusPrerequisitesThere are no prerequisites for PHI20.docx
Course SyllabusPrerequisitesThere are no prerequisites for PHI20.docxmarilucorr
 
COURSE SYLLABUSData Analysis and Reporting Spring 2019.docx
COURSE SYLLABUSData Analysis and Reporting Spring 2019.docxCOURSE SYLLABUSData Analysis and Reporting Spring 2019.docx
COURSE SYLLABUSData Analysis and Reporting Spring 2019.docxmarilucorr
 
COURSE SYLLABUS ADDENDUM INTEGRATED CASE ANALYSIS CRITERIA.docx
COURSE SYLLABUS ADDENDUM INTEGRATED CASE ANALYSIS CRITERIA.docxCOURSE SYLLABUS ADDENDUM INTEGRATED CASE ANALYSIS CRITERIA.docx
COURSE SYLLABUS ADDENDUM INTEGRATED CASE ANALYSIS CRITERIA.docxmarilucorr
 
Course SuccessHabits Matter1. Professors are influenced by you.docx
Course SuccessHabits Matter1. Professors are influenced by you.docxCourse SuccessHabits Matter1. Professors are influenced by you.docx
Course SuccessHabits Matter1. Professors are influenced by you.docxmarilucorr
 
Course ScenarioYou have been hired as the Human Resources Di.docx
Course ScenarioYou have been hired as the Human Resources Di.docxCourse ScenarioYou have been hired as the Human Resources Di.docx
Course ScenarioYou have been hired as the Human Resources Di.docxmarilucorr
 
Course ScenarioPresently, your multinational organization us.docx
Course ScenarioPresently, your multinational organization us.docxCourse ScenarioPresently, your multinational organization us.docx
Course ScenarioPresently, your multinational organization us.docxmarilucorr
 
COURSE RTM 300 (Recreation and Community Development (V. Ward)).docx
COURSE RTM 300 (Recreation and Community Development (V. Ward)).docxCOURSE RTM 300 (Recreation and Community Development (V. Ward)).docx
COURSE RTM 300 (Recreation and Community Development (V. Ward)).docxmarilucorr
 
Course Retail ManagementPart1DraftPart2Fin.docx
Course Retail ManagementPart1DraftPart2Fin.docxCourse Retail ManagementPart1DraftPart2Fin.docx
Course Retail ManagementPart1DraftPart2Fin.docxmarilucorr
 

More from marilucorr (20)

Cover LetterOne aspect of strategic planning is to develop a str.docx
Cover LetterOne aspect of strategic planning is to develop a str.docxCover LetterOne aspect of strategic planning is to develop a str.docx
Cover LetterOne aspect of strategic planning is to develop a str.docx
 
Cover Letter, Resume, and Portfolio Toussaint Casimir.docx
Cover Letter, Resume, and Portfolio Toussaint Casimir.docxCover Letter, Resume, and Portfolio Toussaint Casimir.docx
Cover Letter, Resume, and Portfolio Toussaint Casimir.docx
 
Cover Executive Summary (mention organization, key ‘out-take.docx
Cover Executive Summary (mention organization, key ‘out-take.docxCover Executive Summary (mention organization, key ‘out-take.docx
Cover Executive Summary (mention organization, key ‘out-take.docx
 
couse name Enterprise risk management  From your research, dis.docx
couse name  Enterprise risk management  From your research, dis.docxcouse name  Enterprise risk management  From your research, dis.docx
couse name Enterprise risk management  From your research, dis.docx
 
Courts have reasoned that hospitals have a duty to reserve their b.docx
Courts have reasoned that hospitals have a duty to reserve their b.docxCourts have reasoned that hospitals have a duty to reserve their b.docx
Courts have reasoned that hospitals have a duty to reserve their b.docx
 
Court Operations and Sentencing GuidelinesPeriodically, se.docx
Court Operations and Sentencing GuidelinesPeriodically, se.docxCourt Operations and Sentencing GuidelinesPeriodically, se.docx
Court Operations and Sentencing GuidelinesPeriodically, se.docx
 
Course Competencies Learning ObjectivesCourse Learning Objectiv.docx
Course Competencies Learning ObjectivesCourse Learning Objectiv.docxCourse Competencies Learning ObjectivesCourse Learning Objectiv.docx
Course Competencies Learning ObjectivesCourse Learning Objectiv.docx
 
Coursework 2 – Presentation Report The aim of this 1000-word r.docx
Coursework 2 – Presentation Report  The aim of this 1000-word r.docxCoursework 2 – Presentation Report  The aim of this 1000-word r.docx
Coursework 2 – Presentation Report The aim of this 1000-word r.docx
 
CourseOverview-MarketingChannelConceptsLecture1.docx
CourseOverview-MarketingChannelConceptsLecture1.docxCourseOverview-MarketingChannelConceptsLecture1.docx
CourseOverview-MarketingChannelConceptsLecture1.docx
 
course-text-booksKeri E. Pearlson_ Carol S. Saunders - Managing.docx
course-text-booksKeri E. Pearlson_ Carol S. Saunders - Managing.docxcourse-text-booksKeri E. Pearlson_ Carol S. Saunders - Managing.docx
course-text-booksKeri E. Pearlson_ Carol S. Saunders - Managing.docx
 
COURSE  InfoTech in a Global Economy Do you feel that countri.docx
COURSE  InfoTech in a Global Economy Do you feel that countri.docxCOURSE  InfoTech in a Global Economy Do you feel that countri.docx
COURSE  InfoTech in a Global Economy Do you feel that countri.docx
 
Course Themes Guide The English 112 course will focus o.docx
Course Themes Guide  The English 112 course will focus o.docxCourse Themes Guide  The English 112 course will focus o.docx
Course Themes Guide The English 112 course will focus o.docx
 
Course SyllabusPrerequisitesThere are no prerequisites for PHI20.docx
Course SyllabusPrerequisitesThere are no prerequisites for PHI20.docxCourse SyllabusPrerequisitesThere are no prerequisites for PHI20.docx
Course SyllabusPrerequisitesThere are no prerequisites for PHI20.docx
 
COURSE SYLLABUSData Analysis and Reporting Spring 2019.docx
COURSE SYLLABUSData Analysis and Reporting Spring 2019.docxCOURSE SYLLABUSData Analysis and Reporting Spring 2019.docx
COURSE SYLLABUSData Analysis and Reporting Spring 2019.docx
 
COURSE SYLLABUS ADDENDUM INTEGRATED CASE ANALYSIS CRITERIA.docx
COURSE SYLLABUS ADDENDUM INTEGRATED CASE ANALYSIS CRITERIA.docxCOURSE SYLLABUS ADDENDUM INTEGRATED CASE ANALYSIS CRITERIA.docx
COURSE SYLLABUS ADDENDUM INTEGRATED CASE ANALYSIS CRITERIA.docx
 
Course SuccessHabits Matter1. Professors are influenced by you.docx
Course SuccessHabits Matter1. Professors are influenced by you.docxCourse SuccessHabits Matter1. Professors are influenced by you.docx
Course SuccessHabits Matter1. Professors are influenced by you.docx
 
Course ScenarioYou have been hired as the Human Resources Di.docx
Course ScenarioYou have been hired as the Human Resources Di.docxCourse ScenarioYou have been hired as the Human Resources Di.docx
Course ScenarioYou have been hired as the Human Resources Di.docx
 
Course ScenarioPresently, your multinational organization us.docx
Course ScenarioPresently, your multinational organization us.docxCourse ScenarioPresently, your multinational organization us.docx
Course ScenarioPresently, your multinational organization us.docx
 
COURSE RTM 300 (Recreation and Community Development (V. Ward)).docx
COURSE RTM 300 (Recreation and Community Development (V. Ward)).docxCOURSE RTM 300 (Recreation and Community Development (V. Ward)).docx
COURSE RTM 300 (Recreation and Community Development (V. Ward)).docx
 
Course Retail ManagementPart1DraftPart2Fin.docx
Course Retail ManagementPart1DraftPart2Fin.docxCourse Retail ManagementPart1DraftPart2Fin.docx
Course Retail ManagementPart1DraftPart2Fin.docx
 

Recently uploaded

APM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across SectorsAPM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across SectorsAssociation for Project Management
 
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions  for the students and aspirants of Chemistry12th.pptxOrganic Name Reactions  for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions for the students and aspirants of Chemistry12th.pptxVS Mahajan Coaching Centre
 
URLs and Routing in the Odoo 17 Website App
URLs and Routing in the Odoo 17 Website AppURLs and Routing in the Odoo 17 Website App
URLs and Routing in the Odoo 17 Website AppCeline George
 
Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111Sapana Sha
 
Introduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher EducationIntroduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher Educationpboyjonauth
 
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...Marc Dusseiller Dusjagr
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingTechSoup
 
PSYCHIATRIC History collection FORMAT.pptx
PSYCHIATRIC   History collection FORMAT.pptxPSYCHIATRIC   History collection FORMAT.pptx
PSYCHIATRIC History collection FORMAT.pptxPoojaSen20
 
Mastering the Unannounced Regulatory Inspection
Mastering the Unannounced Regulatory InspectionMastering the Unannounced Regulatory Inspection
Mastering the Unannounced Regulatory InspectionSafetyChain Software
 
Sanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfSanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfsanyamsingh5019
 
Paris 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityParis 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityGeoBlogs
 
MENTAL STATUS EXAMINATION format.docx
MENTAL     STATUS EXAMINATION format.docxMENTAL     STATUS EXAMINATION format.docx
MENTAL STATUS EXAMINATION format.docxPoojaSen20
 
Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991
Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991
Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991RKavithamani
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introductionMaksud Ahmed
 
Contemporary philippine arts from the regions_PPT_Module_12 [Autosaved] (1).pptx
Contemporary philippine arts from the regions_PPT_Module_12 [Autosaved] (1).pptxContemporary philippine arts from the regions_PPT_Module_12 [Autosaved] (1).pptx
Contemporary philippine arts from the regions_PPT_Module_12 [Autosaved] (1).pptxRoyAbrique
 
Accessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactAccessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactdawncurless
 
_Math 4-Q4 Week 5.pptx Steps in Collecting Data
_Math 4-Q4 Week 5.pptx Steps in Collecting Data_Math 4-Q4 Week 5.pptx Steps in Collecting Data
_Math 4-Q4 Week 5.pptx Steps in Collecting DataJhengPantaleon
 
Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3JemimahLaneBuaron
 

Recently uploaded (20)

APM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across SectorsAPM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across Sectors
 
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions  for the students and aspirants of Chemistry12th.pptxOrganic Name Reactions  for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
 
URLs and Routing in the Odoo 17 Website App
URLs and Routing in the Odoo 17 Website AppURLs and Routing in the Odoo 17 Website App
URLs and Routing in the Odoo 17 Website App
 
Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111
 
Introduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher EducationIntroduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher Education
 
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy Consulting
 
PSYCHIATRIC History collection FORMAT.pptx
PSYCHIATRIC   History collection FORMAT.pptxPSYCHIATRIC   History collection FORMAT.pptx
PSYCHIATRIC History collection FORMAT.pptx
 
Mastering the Unannounced Regulatory Inspection
Mastering the Unannounced Regulatory InspectionMastering the Unannounced Regulatory Inspection
Mastering the Unannounced Regulatory Inspection
 
Sanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfSanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdf
 
Paris 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityParis 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activity
 
MENTAL STATUS EXAMINATION format.docx
MENTAL     STATUS EXAMINATION format.docxMENTAL     STATUS EXAMINATION format.docx
MENTAL STATUS EXAMINATION format.docx
 
Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991
Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991
Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introduction
 
Contemporary philippine arts from the regions_PPT_Module_12 [Autosaved] (1).pptx
Contemporary philippine arts from the regions_PPT_Module_12 [Autosaved] (1).pptxContemporary philippine arts from the regions_PPT_Module_12 [Autosaved] (1).pptx
Contemporary philippine arts from the regions_PPT_Module_12 [Autosaved] (1).pptx
 
TataKelola dan KamSiber Kecerdasan Buatan v022.pdf
TataKelola dan KamSiber Kecerdasan Buatan v022.pdfTataKelola dan KamSiber Kecerdasan Buatan v022.pdf
TataKelola dan KamSiber Kecerdasan Buatan v022.pdf
 
Accessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactAccessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impact
 
_Math 4-Q4 Week 5.pptx Steps in Collecting Data
_Math 4-Q4 Week 5.pptx Steps in Collecting Data_Math 4-Q4 Week 5.pptx Steps in Collecting Data
_Math 4-Q4 Week 5.pptx Steps in Collecting Data
 
Staff of Color (SOC) Retention Efforts DDSD
Staff of Color (SOC) Retention Efforts DDSDStaff of Color (SOC) Retention Efforts DDSD
Staff of Color (SOC) Retention Efforts DDSD
 
Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3
 

COURSE PROJECT2Operating System and Application Security Str.docx

  • 1. COURSE PROJECT 2 Operating System and Application Security Strategy (Unit4) Operating System Security Vulnerabilities (list 2 OS)Operating System 1Operating System 2 Antimalware Recommendation (should be specific to your target company and its environment) Intrusion Detection System Recommendation (should be specific to your target company and its environment) Application SecurityWeb-based Infrastructure RecommendationsAS Recommendation 1AS Recommendation 2Database Infrastructure RecommendationsDB Recommendation 1 DB Recommendation 2 Policy Recommendations (See Course Project on Pg. 8 for unit)Policy Recommendation1Policy Recommendation 2 Project: Risk Management Plan Purpose This project provides an opportunity to apply the competencies gained in the lessons of this course to develop a risk management plan for a fictitious organization to replace its outdated plan. Learning Objectives and Outcomes You will gain an overall understanding of risk management, its importance, and critical processes required when developing a
  • 2. formal risk management plan for an organization. Required Source Information and Tools Web References: Links to Web references in this document and related materials are subject to change without prior notice. These links were last verified on April 19, 2015. The following tools and resources that will be needed to complete this project: · Course textbook · Internet access for research Deliverables As discussed in this course, risk management is an important process for all organizations. This is particularly true in information systems, which provides critical support for organizational missions. The heart of risk management is a formal risk management plan. The project activities described in this document allow you to fulfill the role of an employee participating in the risk management process in a specific business situation. The project is structured as follows: Project Part Deliverable Project Part Risk Management Plan – Due 4/17 Submission Requirements All project submissions should follow this format: · Format: Microsoft Word or compatible · Font: Arial, 10-point, double-space · Citation Style: Your school’s preferred style guide Scenario You are an information technology (IT) intern working for Health Network, Inc. (Health Network), a fictitious health services organization headquartered in Minneapolis, Minnesota. Health Network has over 600 employees throughout the
  • 3. organization and generates $500 million USD in annual revenue. The company has two additional locations in Portland, Oregon and Arlington, Virginia, which support a mix of corporate operations. Each corporate facility is located near a co-location data center, where production systems are located and managed by third-party data center hosting vendors. Company Products Health Network has three main products: HNetExchange, HNetPay, and HNetConnect. HNetExchange is the primary source of revenue for the company. The service handles secure electronic medical messages that originate from its customers, such as large hospitals, which are then routed to receiving customers such as clinics. HNetPay is a Web portal used by many of the company’s HNetExchange customers to support the management of secure payments and billing. The HNetPay Web portal, hosted at Health Network production sites, accepts various forms of payments and interacts with credit-card processing organizations much like a Web commerce shopping cart. HNetConnect is an online directory that lists doctors, clinics, and other medical facilities to allow Health Network customers to find the right type of care at the right locations. It contains doctors’ personal information, work addresses, medical certifications, and types of services that the doctors and clinics offer. Doctors are given credentials and are able to update the information in their profile. Health Network customers, which are the hospitals and clinics, connect to all three of the company’s products using HTTPS connections. Doctors and potential patients are able to make payments and update their profiles using Internet-accessible HTTPS Web sites. NOTE: Any discussion of products not a part of this scenario, such as health insurance products, will result in an automatic 50% reduction in points. Your paper is not a research paper on risk management – it is a risk management plan to a very specific situation and must relate to the scenario, above.
  • 4. Information Technology Infrastructure Overview Health Network operates in three production data centers that provide high availability across the company’s products. The data centers host about 1,000 production servers, and Health Network maintains 650 corporate laptops and company-issued mobile devices for its employees. Threats Identified Upon review of the current risk management plan, the following threats were identified: · Loss of company data due to hardware being removed from production systems · Loss of company information on lost or stolen company- owned assets, such as mobile devices and laptops · Loss of customers due to production outages caused by various events, such as natural disasters, change management, unstable software, and so on · Internet threats due to company products being accessible on the Internet · Insider threats · Changes in regulatory landscape that may impact operations Management Request Senior management at Health Network has determined that the existing risk management plan for the organization is out of date and a new risk management plan must be developed. Because of the importance of risk management to the organization, senior management is committed to and supportive of the project to develop a new plan. You have been assigned to develop this new plan. Additional threats other than those described previously may be discovered when re-evaluating the current threat landscape during the risk assessment phase. The budget for this project has not been defined due to senior management’s desire to react to any and all material risks that are identified within the new plan. Given the company’s annual revenue, reasonable expectations can be determined.
  • 5. Project Part 1 Project Part 1 Task 1: Risk Management Plan For the first part of the assigned project, you must create an initial draft of the final risk management plan. To do so, you must: You Risk Management Plan will contain the following sections: 1. A section titled Introduction discussing the purpose of the plan. You must include details from the scenario, above, describing the environment. 10 points. 2. A section titled Scope discussing the scope of the plan. 10 points 3. A section, titled Compliance Laws and Regulations. Using the information in the scenario provided above, discuss regulations and laws with which Health Network must comply. 30 points 4. A section, titled Roles and Responsibilities, that will discuss the different individuals and departments who will be responsible for risk management within the organization (this was presented in your textbook). 20 points 5. A section, titled Risk Mitigation Plan, that discusses the threats identified in the scenario and your proposed mitigations, as well as any new threats.30 points. Write an initial draft of the risk management plan as detailed in the instructions above. Your plan should be made using a standard word processor format compatible with Microsoft Word. Evaluation Criteria and Rubrics · Did the student demonstrate an understanding of the competencies covered in the course thus far? · Did the student include all important components of a risk management plan in the outline? · Did the student demonstrate good research, reasoning, and decision-making skills in identifying key components and compliance laws and regulations? · Did the student create a professional, well-developed draft with proper grammar, spelling, and punctuation?
  • 6. © 2015 by Jones & Bartlett Learning, LLC, an Ascend Learning Company. All rights reserved. www.jblearning.com Page 3 Project: Risk Management Plan © 201 5 by Jones & Bartlett Learning, LLC, an Ascend Learning Company . All rights reserved. www.jblearning.com Page 1 Purpose This project provides an opportunity to apply the competencies gained in the lesson s of this course to develop a risk management plan for a
  • 7. fictitious organization to replace its outdated plan . Learning Objectives and Outcomes You will gain an overall understanding of risk management, its importance, and critical processes required when developing a formal risk m anagemen t p lan for an organization. Required Source Information and Tools Web References: Links to Web references in this document and related materials are subject to change without prior notice. These links were last verified on April 19 , 2015 . The following tools and resources that will be needed to com plete this project:
  • 8. § Course textbook § Internet access for research Deliverables As discussed in this course, risk management is an important process for all organizations. This is particularly true in information systems, which provides critical support for organizational missions. The heart of risk management is a formal risk management plan. Th e project activit ies described in this document allow you to fulfill the role of an employee participating in the risk management process in a specific business situa tion. The project is structured as follows: Project Part
  • 9. Deliverable Project Part Risk Management Plan – Due 4/17 Submission Requirements All project submissions should follow this format: § Format: Microsoft Word or compatible § Font : Arial, 1 0 - point , d ouble - s pace
  • 10. § Citation Style: Your school’s preferred style guide Scenario Project: Risk Management Plan © 2015 by Jones & Bartlett Learning, LLC, an Ascend Learning Company. All rights reserved. www.jblearning.com Page 1 Purpose This project provides an opportunity to apply the competencies gained in the lessons of this course to develop a risk management plan for a fictitious organization to replace its outdated plan. Learning Objectives and Outcomes You will gain an overall understanding of risk management, its importance, and critical processes required when developing a formal risk management plan for an organization. Required Source Information and Tools Web References: Links to Web references in this document and related materials are subject to change without prior notice. These links were last verified on April 19, 2015. The following tools and resources that will be needed to complete this project: Deliverables As discussed in this course, risk management is an important process for all organizations. This is
  • 11. particularly true in information systems, which provides critical support for organizational missions. The heart of risk management is a formal risk management plan. The project activities described in this document allow you to fulfill the role of an employee participating in the risk management process in a specific business situation. The project is structured as follows: Project Part Deliverable Project Part Risk Management Plan – Due 4/17 Submission Requirements All project submissions should follow this format: -point, double-space Scenario