Demonstrate your knowledge of risk-assessment protocols

Assignment Help Other Subject
Reference no: EM133923376

Assignment Directions:

Risk-Assessment Strategy

Purpose
In this assignment, you will detail the risk-assessment plan and strategy for your organization that you described in your discussion post. You have demonstrated that you understand their core business functions and mission. Your risk assessment should be tailored to that understanding. If you implement the risk-management controls recommended by NIST, another standards body, or a trade association for your industry, you will be demonstrating compliance with government requirements. This means that if there is a breach, your legal office can provide a written justification that maps your compliance to your direct business services. This will also support any insurance claims and help to maintain your business reputation. Get online assignment help-AI & plagiarism-free-now!

Directions
Write a detailed overview and analysis of the fundamentals of risk management in cybersecurity for your organization that you described in your discussion post. You may choose one of the following two options for formatting your response (see details below):
Option A: A 4- to 6-page paper OR
Option B: A matrix (sample provided below) and a 2- to 3-page narrative
Regardless of which format you choose, be sure to address all the following elements:
Write a substantive executive summary that includes the following:
A brief statement on the purpose and scope of the RA
Your focus on the current organizational assessment
Your risk-mitigation and management strategy
Cited references to authorities that show the organization's compliance with government requirements, industry best practices (NIST), or other standards Get online assignment help-AI & plagiarism-free-now!
Assess the cybersecurity posture of your chosen organization. Be sure to include the following:
Describe your organization's business goals, mission, objectives, and how the requirements would support them.
Use the implementation tiers in NIST to assess your organization's current situation.
List vulnerabilities, countermeasures, and recommendations for improvement.
Apply the NIST RMF framework:
Explain in more detail how to use NIST 800-53 (rev.5), NIST 800-30, and the new NIST 2.0 to create a comprehensive strategy.
Explain what actions you would take to align your business strategy with the recommended NIST best practices.
Clearly map the business objectives and goals to a cybersecurity plan. Include all the following key measures:
Prepare the organization.
Categorize system and information.
Select a range of 4-6 NIST SP 800-53 controls.
Implement the controls and document how controls were deployed.
Assess whether the controls are in place, operating as intended, and producing the desired outcomes.
Authorize risk-based decision-making.
Continuously monitor implementation and risks to the system.
Evidence of skills: Demonstrate your knowledge of risk-assessment protocols as well as legal and regulatory compliance.
Write the paper with an organized, logical flow of information. Cite authoritative sources sufficiently to show that your analysis is based on the resources provided or other documents you find through your research. Please use a consistent citation style.
Executive Summary Features
Here are some ideas for what to include in your executive summary. A CEO should be able to use your summary for decision-making purposes. An executive summary includes a brief statement of the issue, which helps the executive understand the topic (risk mitigation and management).
As stated in the directions, cite the authorities you are using to show compliance with government requirements, industry best practices (e.g., NIST), or other standards. To analyze the importance of these requirements and best practices, one approach would be to follow the suggestions below.
Explain briefly how the templates and their rationale provide assurances to the CEO that these requirements reduce the organization's cybersecurity risk. One way to do this is to cite a specific requirement as an example and explain how it is applied. Then you may also want to talk briefly about a technological solution you are using to assist you in this effort. You can then list some of the vulnerabilities your organization has in the system and explain how you will address them, Finally, you could discuss how you will make sure that you are ensuring compliance (e.g., continuous monitoring, establishing a training program that requires quarterly testing, or some other methods that demonstrate active participation).

Reference no: EM133923376

Questions Cloud

How are hurricanes and earthquakes alike : Compare and Contrast How are hurricanes and earthquakes alike?
Advocates of holistic-safe and quality care : Examine roles and competencies of advanced practice nurses essential to performing as leaders and advocates of holistic, safe, and quality care.
Write an essay about the crime of the century : Write an essay about The Crime of the Century, Tell me about Sacco and Vanzetti and their murder trial. Was this a case of discrimination against immigrants?
How much did alec tricity gain or lose : Did Alec Tricity make money or lose money. If so, how much did he gain or lose? What was his percentage return? What is this process called?
Demonstrate your knowledge of risk-assessment protocols : Implement the controls and document how controls were deployed. Assess whether the controls are in place, operating as intended, and producing the desired
Why the felony murder doctrine should not be abolished : I need help closing out my debate speech about why the felony murder doctrine should NOT be abolished.
Priority of care for patient diagnose with parkinson disease : What are the top priority of care for a patient diagnose with Parkinson disease and the rationale? What are nursing intervention for the priority stated
What is his tax liability before his payroll taxes : What is his tax liability before his payroll taxes? He had his company withhold $20,000 in taxes. Is there a refund? If so how much? Does he owe taxes?
Most common conditions screened for at birth : Congenital audiological disorders are among the most common conditions screened for at birth. The incidence rate of hearing loss at birth in Texas is:

Reviews

Write a Review

Other Subject Questions & Answers

  Cross-cultural opportunities and conflicts in canada

Short Paper on Cross-cultural Opportunities and Conflicts in Canada.

  Sociology theory questions

Sociology are very fundamental in nature. Role strain and role constraint speak about the duties and responsibilities of the roles of people in society or in a group. A short theory about Darwin and Moths is also answered.

  A book review on unfaithful angels

This review will help the reader understand the social work profession through different concepts giving the glimpse of why the social work profession might have drifted away from its original purpose of serving the poor.

  Disorder paper: schizophrenia

Schizophrenia does not really have just one single cause. It is a possibility that this disorder could be inherited but not all doctors are sure.

  Individual assignment: two models handout and rubric

Individual Assignment : Two Models Handout and Rubric,    This paper will allow you to understand and evaluate two vastly different organizational models and to effectively communicate their differences.

  Developing strategic intent for toyota

The following report includes the description about the organization, its strategies, industry analysis in which it operates and its position in the industry.

  Gasoline powered passenger vehicles

In this study, we examine how gasoline price volatility and income of the consumers impacts consumer's demand for gasoline.

  An aspect of poverty in canada

Economics thesis undergrad 4th year paper to write. it should be about 22 pages in length, literature review, economic analysis and then data or cost benefit analysis.

  Ngn customer satisfaction qos indicator for 3g services

The paper aims to highlight the global trends in countries and regions where 3G has already been introduced and propose an implementation plan to the telecom operators of developing countries.

  Prepare a power point presentation

Prepare the power point presentation for the case: Santa Fe Independent School District

  Information literacy is important in this environment

Information literacy is critically important in this contemporary environment

  Associative property of multiplication

Write a definition for associative property of multiplication.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd