Discuss how fmc should remediate the risks

Assignment Help Computer Engineering
Reference no: EM133991351

Case Scenario

Fielder Medical Center (FMC) is a federally funded healthcare facility that seeks to expand its business into the local sale of medical equipment. As FMC sought to improve its data management in alignment with digitization goals, it implemented a system to manage the licensing, certificates, and relevant professional documents for the doctors working at FMC. Doctors are required to log in and upload sensitive artifacts that prove they are current in their licensing to practice. These artifacts may contain personally identifiable information about the doctor, including real name, home address, social security number, and other sensitive data.

Aside from the digitization of data for convenient management within FMC, the main purpose of this system is to allow access by the government for the purpose of validating information and securing federal funds on a recurring annual basis.

Concerns about security were discussed at a recent board meeting, and an external security consulting firm was hired to conduct a security assessment of FMC's systems. This report identifies several potential compliance issues that would require the system security plan (SSP) to be updated, including security controls that are in place or planned for meeting system requirements.

As FMC's CISO (Chief Information Security Officer), you are responsible for identifying and developing a cyber strategy to address the risks identified in the attached "Security Assessment Report for Fielder Medical Center" to ensure that FMC's security posture is brought into alignment with the Federal Information Security Management Act (FISMA) requirements. As the new FMC system includes only doctor information and does not include patient information, compliance focuses on FISMA requirements instead of the Health Insurance Portability and Accountability Act (HIPAA) Security Rule requirements. No AI shortcuts - Just Genuine Assignment Help from Real Tutors.

A. Summarize the gaps that currently exist in the company's security framework as described in the attached "Security Assessment Report for Fielder Medical Center" (SAR).

B. For each of the five identified controls in Section 3.3 of the SAR, do the following:

1. Identify the associated risk rating as low, moderate, or high and explain the risk.

2. Justify FMC's decision to remediate the risk associated with the identified control instead of accepting the risk based on compliance and industry guidelines and support the justification with industry-respected sources.

Note: Be sure to include all five controls in part B1, and all five controls in part B2. Your submission will be returned if one or more controls are missing from part B1 or part B2.

C. Discuss how FMC should remediate the risks with each of the five controls identified in Section 3.3 of the SAR. For each risk, include any assets, actions, or changes that will be needed for remediation.

Note: Be sure to include all five controls from part B. Your submission will be returned if one or more controls are missing from part C.

D. Develop a PCI DSS (Payment Card Industry Data Security Standard) -compliant policy to address the three concerns identified in Section 3.2.4 of the SAR, including the roles and responsibilities associated for each requirement identified within the SAR to meet PCI DSS compliance.

Reference no: EM133991351

Questions Cloud

End-stage kidney disease : Thomas is an 85-year-old, Caucasian male who has been admitted to the hospital for the past two weeks related to his end-stage kidney disease.
Health assessment and communication : What knowledge or information used in this course health assessment and communication are you applying as a nurse ?
Physical therapist and occupational therapist : What are the differences between a Physical Therapist and an Occupational Therapist?
Calculate safe heparin dosages based on weight : Recognize the normal and common dysrhythmias associated with the cardiac conduction system. Calculate safe heparin dosages based on weight.
Discuss how fmc should remediate the risks : Discuss how FMC should remediate the risks with each of the five controls identified in Section 3.3 of the SAR. For each risk, include any assets
Wealthy country engage in practice or policy : If a wealthy country engage in a practice or policy that makes the health of those in poorer countries worse
Advantages and disadvantages of cloud computing : Be sure to identify the stakeholders who need to be involved and the discussions that need to take place. Evaluate the advantages and disadvantages of cloud
Carcinogens associated with breast cancer development : Discuss common carcinogens associated with breast cancer development.
What needs are unsatisfied and would potentially make switch : Carefully read the Introduction section on the Kano Model. What needs are unsatisfied and would potentially make you switch products or services?

Reviews

Write a Review

Computer Engineering Questions & Answers

  Mathematics in computing

Binary search tree, and postorder and preorder traversal Determine the shortest path in Graph

  Ict governance

ICT is defined as the term of Information and communication technologies, it is diverse set of technical tools and resources used by the government agencies to communicate and produce, circulate, store, and manage all information.

  Implementation of memory management

Assignment covers the following eight topics and explore the implementation of memory management, processes and threads.

  Realize business and organizational data storage

Realize business and organizational data storage and fast access times are much more important than they have ever been. Compare and contrast magnetic tapes, magnetic disks, optical discs

  What is the protocol overhead

What are the advantages of using a compiled language over an interpreted one? Under what circumstances would you select to use an interpreted language?

  Implementation of memory management

Paper describes about memory management. How memory is used in executing programs and its critical support for applications.

  Define open and closed loop control systems

Define open and closed loop cotrol systems.Explain difference between time varying and time invariant control system wth suitable example.

  Prepare a proposal to deploy windows server

Prepare a proposal to deploy Windows Server onto an existing network based on the provided scenario.

  Security policy document project

Analyze security requirements and develop a security policy

  Write a procedure that produces independent stack objects

Write a procedure (make-stack) that produces independent stack objects, using a message-passing style, e.g.

  Define a suitable functional unit

Define a suitable functional unit for a comparative study between two different types of paint.

  Calculate yield to maturity and bond prices

Calculate yield to maturity (YTM) and bond prices

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd