Reference no: EM133985131
Question
Assume the role of an IT security manager for Health Network, Inc. (Health Network), a fictitious health services organization headquartered in Minneapolis, Minnesota. Health Network has over 600 employees and generates $500 million USD in annual revenue. The company has two additional locations in Portland, Oregon, and Arlington, Virginia, which support a mix of corporate operations. Each corporate facility is located near a co-location data center, where production systems are located and managed by third-party data center hosting vendors.
You are tasked with determining appropriate risk management techniques for identified threats and vulnerabilities by creating a summary report for the senior management to review.
1. Identify and describe five threat/vulnerability pairs that pose a risk to the organization.
2. Estimate and explain the likelihood of occurrence (low, medium, or high) of each threat/vulnerability pair.
3. Prioritize the risks.
4. Describe how you would handle each risk, such as avoiding, sharing, mitigating, or accepting the risk. Justify each decision.