Describe three of the cobit p09 control objectives

Assignment Help Management Information Sys
Reference no: EM131273739

1:Health care organizations must strictly comply with the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security rules that require organizations to have proper security controls for handling personal information referred to as "protected health information," or PHI. This includes security controls for the IT infrastructure handling PHI. Which of the listed risks, threats, or vulnerabilities can violate HIPAA privacy and security requirements? List one and justify your answer in one or two sentences.

2. How many threats and vulnerabilities did you find that impacted risk in each of the seven domains of a typical IT infrastructure?

3. Which domain(s) had the greatest number of risks, threats, and vulnerabilities?

4. What is the risk impact or risk factor (critical, major, and minor) that you would qualitatively assign to the risks, threats, and vulnerabilities you identified for the LAN-to-WAN Domain for the health care and HIPAA compliance scenario?

5. Of the three System/Application Domain risks, threats, and vulnerabilities identified, which one requires a disaster recovery plan and business continuity plan to maintain continued operations during a catastrophic outage?

6. Which domain represents the greatest risk and uncertainty to an organization?

7. Which domain requires stringent access controls and encryption for connectivity to corporate resources from home?

8. Which domain requires annual security awareness training and employee background checks for sensitive positions to help mitigate risks from employee sabotage?

9. Which domains need software vulnerability assessments to mitigate risk from software vulnerabilities?

10. Which domain requires acceptable use policies (AUPs) to minimize unnecessary user-initiated Internet traffic and can be monitored and controlled by Web content filters?

11. In which domain do you implement Web content filters?

12. If you implement a Wireless LAN (WLAN) to support connectivity for laptops in the Workstation Domain, which domain does WLAN fall within?

13. Under the Gramm-Leach-Bliley-Act (GLBA), banks must protect customer privacy. A given bank has just implemented its online banking solution that allows customers to access their accounts and perform transactions via their computers or personal digital assistant (PDA) devices.

Online banking servers and their public Internet hosting would fall within which domains of security responsibility?

14. True or false: Customers who conduct online banking on their laptops or personal computers must use Hypertext Transfer Protocol Secure (HTTPS), the secure and encrypted version of Hypertext Transfer Protocol (HTTP) browser communications. HTTPS encrypts Web page data inputs and data through the public Internet and decrypts that Web page and data on the user's PC or device.

15. Explain how a layered security strategy throughout the seven domains of a typical IT infrastructure can help mitigate risk exposure for loss of privacy data or confidential data from the System/Application Domain.

16.What is COBIT P09's purpose?

17. Name three of COBIT's six control objectives.

18.For each of the threats and vulnerabilities from the Identifying Threats and Vulnerabilities in an IT Infrastructure lab in this lab manual (list at least three and no more than five) that you have remediated, what must you assess as part of your overall COBIT P09 risk management approach for your IT infrastructure?

19. True or false: COBIT P09 risk management control objectives focus on assessment and management of IT risk.

20. What is the name of the organization that defined the COBIT P09 Risk Management Framework?

21. Describe three of the COBIT P09 control objectives.

22. Describe three of the COBIT P09.1 IT Risk Management Framework control objectives.

Reference no: EM131273739

Questions Cloud

Create a gantt chart illustrating the project tasks : Define five (5) major tasks, each with one to two (1-2) subtasks. Also write a brief description for each task.3. Create a Gantt chart illustrating the project tasks (use Microsoft Project or a similar project management program).
Break-even point analysis : An electric item manufacturing company produces extension cords, has a variable cost of production $2.50 per unit and a selling price of $5.00 per unit. Fixed costs are $15,000. Current sales volume is 10,000 units.  ariable cost would increase to $...
How do they use supply chain management : Evaluate REI in this discussion. Outline their current channel and methods of distribution. How do they use Supply Chain Management? Does it work well? Any suggestions for improvement?
In deciding which channel to use in a specific communication : In deciding which channel to use in a specific communication situation, list at least four factors that should be considered and briefly explain why each is important
Describe three of the cobit p09 control objectives : For each of the threats and vulnerabilities from the Identifying Threats and Vulnerabilities in an IT Infrastructure lab in this lab manual (list at least three and no more than five) that you have remediated, what must you assess as part of your ..
Identifying as many factors as possible in the categories : You are to conduct a country/industry risk report, identifying as many factors as possible in the categories listed above for the analysis. Present your findings in a report of 10-12 pages.
Dozer is used in a pushing operation : A CAT D7H (power-shift) dozer is used in a pushing operation. The dozer is equipped with a straight blade. The material (dry and noncohesive) weighs 98 pcf in the bank state. It is estimated that the material will swell 6%, from bank to loose state. ..
Borders over a specified period of time : GDP is the total market value of final goods and services produced within a nation's borders over a specified period of time, usually one year. Go through the definition and find 3 words or phrases and explain how those words and phrases indicat..
Draw a diagram to show price-quantity : Assume a pharmaceutical company has a ten year patent to produce a drug exclusively. Moreover, assume the marginal cost of producing this drug is fixed. a) Draw a diagram to show price, quantity, and profit from the sale of this drug during the pa..

Reviews

Write a Review

Management Information Sys Questions & Answers

  Information technology and the changing fabric

Illustrations of concepts from organizational structure, organizational power and politics and organizational culture.

  Case study: software-as-a-service goes mainstream

Explain the questions based on case study. case study - salesforce.com: software-as-a-service goes mainstream

  Research proposal on cloud computing

The usage and influence of outsourcing and cloud computing on Management Information Systems is the proposed topic of the research project.

  Host an e-commerce site for a small start-up company

This paper will help develop internet skills in commercial services for hosting an e-commerce site for a small start-up company.

  How are internet technologies affecting the structure

How are Internet technologies affecting the structure and work roles of modern organizations?

  Segregation of duties in the personal computing environment

Why is inadequate segregation of duties a problem in the personal computing environment?

  Social media strategy implementation and evaluation

Social media strategy implementation and evaluation

  Problems in the personal computing environment

What is the basic purpose behind segregation of duties a problem in the personal computing environment?

  Role of it/is in an organisation

Prepare a presentation on Information Systems and Organizational changes

  Perky pies

Information systems to adequately manage supply both up and down stream.

  Mark the equilibrium price and quantity

The demand schedule for computer chips.

  Visit and analyze the company-specific web-site

Visit and analyze the Company-specific web-site with respect to E-Commerce issues

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd