Instruction
Review NIST 800-37 and Chapter 3 regarding the overview of Risk Management and the processes. Consider each heading as Part 1–4 of the risk management process. This assignment will require all parts to conduct a full risk assessment against their organization based on the information obtained from previous assignments, provide a synopsis on how to manage identified risks, and describe the tools and strategies that will ensure network security.
Prerequisite: Using a vulnerability scanner obtained from previous assignment, conduct a full scan against all servers in domain, evaluate the open vulnerabilities within the domain. (This information will be used in Part 3 of the assignment.)
Use the following guidelines to create a four- to five-page MS Word document using the same corporate profile selected earlier:
Part 1: Prepare for Risk Management ("Establish a framework for managing risk.")
List the corporate requirements (i.e., standards, laws) associated with the company. Briefly explain the impact of non-compliance.
Develop categories and a classification method for company information systems. List at least eight categories for various people, processes, hardware, software, and data applicable to the company. Describe the data/system classification scheme to use reasons for selecting it.
Part 2: Identify Risk ("Where is the risk to my information assets?")
List a minimum of 20 assets (data, systems, people, processes, etc.) and measure value to company (Low, Moderate, High, Critical) in a simple table.
In a column, identify assets that can impact company compliance, customer satisfaction, competitive advantage, or business productivity (i.e., Business Impact Analysis).
Part 3: Assess Risk ("How severe is the risk to my information assets?")
Provide a picture, diagram, or matrix that is used to assess risk.
Define for each asset identified the potential threats, the likelihood the threat will occur or is successful, and the impact loss of asset will have on company. Note: This includes disasters, loss of power, employee resignations, system malfunctions, drop in customers, etc.
Using the vulnerability scan, list in a table a minimum of 15 identified threats (open vulnerabilities) to the information systems, impact of the exploited vulnerability, and remediation steps (countermeasures) to remove or reduce either impact or likelihood from threat.
Part 4: Define Risk Appetite ("How much risk is acceptable to my organization?")
Review the characteristics of a risk appetite in the course text.
Establish a Risk Appetite Statement for the company.
Define the Risk Tolerance of the company.
Part 5: Control Risk
In two to four paragraphs (300-500 words) identify and describe the Risk Control Strategy adopted by the company. Ensure the strategy is in alignment with corporate requirements (Standards, Laws, Frameworks, etc.) and Risk Appetite.