Instruction
The hospitals IT architecture consists of a campus WAN with three main office buildings operating inside of the campus network; the main hospital, the children's hospital, and the research and administrative building.
During the audit, there were many findings inside of the organization that included:
Numerous HIPAA violations around data security and handling.
Multiple accounts with unnecessary administrative privileges.
Sensitive areas of the environment that were not segregated from the rest of the network (i.e. a flat network).
Remote employees had access to sensitive resources from outside the organization without the use of any secure means of access.
Physical areas of the IT facilities were not secured or otherwise easily accessible.
Hundreds of endpoints that were not updated with the latest OS and patches.
Weak or default passwords in use across the network with no multi-factor authentication.
Poor documentation with generic policies and standards.
The action is on your team to develop a project plan, and presentation to key leadership on how best to mitigate each of these findings. If the approach and design strategy are approved by the executive leadership, you may receive additional business for carrying out these remediations.
Additional Notes
I highly recommend you research HIPAA compliance and checklist documentation. Specifically, around the areas of data handling and classifications.
The network architecture and design is intentionally vague. I want you to leverage some of the things discussed in class topics (I.e. VLANs, Firewalls, DMZs, Multi-Factor, etc.) to help address the findings in this project plan. Be sure to account for defense- in-depth security. Missing layers of security will be points marked against the total score.
Length 2,000-2,500 word to discuss your proposed plan.
Format your paper consistent with MLA guidelines.