Task Description You are hired by Advanced Medicos Limited (AML), a healthcare product sell company, as a cybersecurity consultant to help in security management and to address the contemporary and...

1 answer below »
Task Description You are hired by Advanced Medicos Limited (AML), a healthcare product sell company, as a cybersecurity consultant to help in security management and to address the contemporary and emerging risks from the cyber threats the company is facing. AML is providing a platform for Australian customers to sell their product online. The vision of the company is to be among the top 5 nation-wide. The board from the advice by Chief Information Officer (CIO) and Chief Information Security Officer (CISO) has concluded that they should get to point that the key services such as web portal should be able to recover from major incidents in less than 20 minutes while other services can be up and running in less than 1 hour. In case of a disaster, they should be able to have the Web portal and payroll system fully functional in less than 2 days.

The company is a new company which is growing rapidly. While the company uses its database server to store the information of its customers’ private data, credit card info, etc. it has a poordesigned network with a low level of security. As the company is responsible for the privacy and the security of customer personal info, credit card details, the security of payment transactions, etc. they have decided to improve their information security. Therefore, they have hired you to do the following task:

- Risk assessment exercise: perform a full cyber risk assessment exercise for this company and document the outcomes.

CMP73001-Ass1

Existing IT infrastructure of AML: - Office 365 Emails Hosting - 2 Web server providing web services and payment options - A physical database server storing customer information - DHCP and DNS servers - Servers located in a server room accessible by all staff - There is no virtual/cloud storage - The backup files are stored on a single computer connected to the internal network - Two 24-port Cisco Catalyst switches (1Gbps ports) - Switches are access layer switches - ADSL router - 40 PCs with outdated antivirus - The operating systems used in the company are Windows 2012 server and Windows 10 - Windows Firewalls are on - No security configuration on routers and switches - Telnet connection is used by IT people to remotely check the configuration of the network devices. Therefore, there is no encryption in remote access. - Two wireless access points - Wireless security is WPA - 10 Voice over IP phones - Servers located in a server room accessible by all staff - There is no virtual/cloud storage - The backup files are stored on a single computer connected to the internal network - There are 40 staff including three IT people (IT staff are responsible to look after internet connection, network devices, Wi-Fi, Voice over IP service, LAN, computers, servers, hardware and software, and video conference facilities). - All staff and equipment are on a single floor. - The roles and responsibilities of people who are responsible for information security management are not clear and they are not documented. All IT staff help in information security management.

For this assignment, you need to write a report to the CEO of the company and answer a number of questions. You should also identify assets, perform risk assessment, and propose solutions to mitigate risks. Your answer should be submitted in PDF/DOC files.

Assignment-1 guideline

Risk assessment exercise: perform a full cyber risk assessment exercise for AML and document the outcome.

CMP73001-Ass1

Task 1: Identify and manage asset

1.1 To perform a risk assessment for this company, you should first identify all information assets and their business values. This is necessary because unidentified assets are not considered in risk assessment. In this question, you need to identify information assets based on your judgment and then perform the asset classification. You should classify information assets as different categories of assets which might need different protection based on their sensitivity and their value. Make a table for your task 1 and add the following information in your table: a. provide a list of assets (at least 10 assets should be identified) and provide a meaningful description for the assets e.g. what is it used for, and what is included etc. b. determine the asset location and ownership, assign a unique ID for the asset. Each id should give some hint about the asset. For instance, HW.01 can be interpreted as Hardware Asset number 1. c. classify the identified assets based on their sensitivity. The identified classes should be based on your understanding and experience of each asset. You need to do some research and find at least three common classes of information assets. Create a Weighting Factor Analysis (WFA) to rank the identified assets.

To complete this task you need to search for asset classification samples. The following links also give you the required information about assets classes.

https://policy.usq.edu.au/documents/13931PL https://www.flinders.edu.au/content/dam/documents/staff/policies/facilities-infomanagement/information-classification-handling-procedures.pdf https://cdn-images-1.medium.com/max/1200/1*AXioKlJPercQVPvEm-tt-A.png

1.2 Explain how information security governance can help AML to have efficient asset management.

1.3 To improve the level of cybersecurity in AML, you should develop some security policies. The policies should cover different assets like people, technology, access control, etc. The links below give you some examples of information security policies. For this question, at least 5 policies should be provided. It is expected that you first create your Enterprise security or enterprise information policy.

https://policies.newcastle.edu.au/document/view-current.php?id=135 https://sydney.edu.au/policies/showdoc.aspx?recnum=PDOC2011/141&RendNum=0

CMP73001-Ass1

Task 2: Vulnerability management and risk management 2.1 Do some research about different steps of Enterprise Risk Management by ISO framework and briefly explain each step.

2.2 Identify vulnerabilities in the company assets and their threats. This information should be shown in a table called vulnerability assessment table (TVA worksheet). One extra column should be added for brief vulnerability analysis.

2.3 Now, you are responsible to develop a risk management strategy to mitigate the existing risks to an acceptable level. You should use this template to create your strategy.

2.4 Create a risk assessment table including the identified threats and vulnerabilities, the likelihood of their occurrence, the expected impact of the threats on the company’s operations, and the risk rating.

You should answer this question based on your answer to question 2.2 and based on the experience that you gained in the basic Cybersecurity unite. The risk analysis matrix should be used in this task.

The following link helps you to create your risk assessment table. On Page 10 of this file, there is an example of risk assessment. Make a similar table for this question.

https://itsecurity.uiowa.edu/sites/itsecurity.uiowa.edu/files/sampleriskassessmentreport.pdf

Assessment Criteria

Criteria Max Mark

Task1: Identify and manage asset 12 Task 1.1 a & b: identify assets and other required information 3 Task 1.1 c: Classify the identified assets 4 Tasks 1.2 & 1.3: explain the importance of information security governance and develop security policies 5 Task 2: Vulnerability management and risk management 15 Task 2.1: Describe risk management phases in ISO framework 3 Task 2.2: identify vulnerabilities and their threats 4 Task 2.3: develop a risk management strategy 3 Task 2.4: perform risk assessment 5 Documentation 3 Professional presentation. 1.5 Referencing 1.5 Total 30

CMP73001-Ass1

Assignment-1 Marking Rubric A spreadsheet that will be used for the marking of your site is provided (attached with the final submission link) on MySCU to itemize exactly what tutors will be looking at in relation to marking your assignment. It contains a detailed breakdown of the marking criteria for this assignment. I strongly suggest you peruse this spreadsheet.

Format, Presentation and Submission Format

There is no report template to be used in this assignment, so you can design your own template or refer to online resources. However, the report should be well presented in a standard report format. The first page of the report should have a simple company logo, your name, and student ID, CMP73001 Assignment 1, and the date you submit your assignment.

When you have completed the assignment, you are required to submit your assignment in the PDF/DOC format. The file will be named using the following convention:

filename = FirstInitialYourLastName_CMP73001_A1.pdf (i.e. FJones_CMP73001_A1.pdf)

Original Work

Note that you are not allowed to cut and paste from online resources. Use your own words and figures. Acknowledge all reference sources.

It is a University requirement that a student’s work complies with the Academic Integrity Policy. It is a student’s responsibility to be familiar with the Policy. Failure to comply with the Policy can have severe consequences in the form of University sanctions. For information on this Policy please refer to Student Academic Integrity policy at the following website:

http://policies.scu.edu.au/view.current.php?id=00141

As part of a University initiative to support the development of academic integrity, assessments may be checked for plagiarism, including through an electronic system, either internally or by a plagiarism checking service, and be held for future checking and matching purposes.

A Turnitin link has been set up to provide you with an opportunity to check the originality of your work until your due date. Please make sure you review the report generated by the system and make changes (if necessary!) to minimise the issues of improper citation or potential plagiarism. If you fail to follow this step, your report may not be graded or may incur late feedback.

CMP73001-Ass1
Answered Same DayApr 05, 2021CMP73001Southern Cross University

Answer To: Task Description You are hired by Advanced Medicos Limited (AML), a healthcare product sell company,...

Akriti answered on Apr 08 2021
157 Votes
Risk Assessment Exercise
Answer 1.1
    Assets Classified
    Description
    Asset owner/location
    Class of Asset
    ID
    WFA
    Physical asset database
    It is the database which stores all the relevant information in it
    Owner/Director
Of information asset
    Restricted Informati
on
    HW.01
    9
    40 PCs
    These are the main hardware system through which all the working takes place
    Employee assigned to it
    Internal Information
    HW.01
    10
    Web Servers
    It is a system/computer which runs websites
    IT Team
    Public
Information
    SW.01
    7
    Windows firewall
    It helps in preventing unauthorized access to or from private network
    IT Team
    Internal Information
    SW.01
    9
    Computer with backup file
    System which upheld all the backup data which can be used in case of any incontinency
    IT Team
    Restricted Information
    HW.01
    8
    Operating system
    It is the interface which connects the computer and the user
    IT Team
    Internal Information
    SW.01
    8
    IT staff
    These are the personnel which looks after the IT in the company
    Owner/Director
Of information asset
    Internal Information
    HR.01
    9
    Switches
    Establishes connection between end node devices with network
    IT Team
    Internal Information
    HW.01
    7
    Routers
    It helps in sharing data packets between multiple networks
    IT Team
    Internal Information
    SW.01
    8
    
Wireless security
    
It helps In securing any malicious attack or unauthorized access
    IT Team
    
Restricted Information
    
SW.01
    8
Answer 1.2
Information security governance is a part of corporate governance. It comprises three elements which are participation, accountability and transparency. The corporate governance can be said to the governance that is implied over the company for the all managerial work.
The mix of all software, hardware comprises of the IT assets of the company. To make sure the integrity of the system is not compromised, maintenance and updating is required on regular basis. Upgrading or renewal of asset should be done if any issue arises under operational excellence, future orientation or accountability. For asset management there should be a policy for upgrading or renewal, support and contractual detail all of which individually or combined are relevant inputs to an information concerning asset (McDermid, Mahncke,et al, 2010).
Answer 1.3
Security policies build are:
· Information Security Policy
· Cyber Security Policy
· Incident response Policy
· Physical Security Policy
· Access Control Policy
· Information Security Policy- This policy serves the purpose of securing the information of the enterprise.
Human Resource: All personnel should be in adherence to Human Resource Information Security Guidelines during any time of employment.
Access Control:...
SOLUTION.PDF

Answer To This Question Is Available To Download

Related Questions & Answers

More Questions »

Submit New Assignment

Copy and Paste Your Assignment Here