Reference no: EM133248948
Assignment Title - Evaluate Risk Implied Within Data Assets and Related Systems in an Organization
Books and Resources -
Jones, J. A. (2006). An Introduction to Factor Analysis of Information Risk (FAIR). Norwich University Journal of Information Assurance (NUJIA), 2(1), 1-66.
Amin, Z. (2019). A practical road map for assessing cyber risk. Journal of Risk Research, 22(1), 32-43.
Graubart, R. & Bodeau, D. (2016). Risk management framework and cyber resiliency. MITRE Corporation.
Instructions - In this assignment, you will categorize and evaluate the internal and external risks to an organization's critical systems. As CISO of a mid-sized manufacturing company, you've been tasked to oversee a risk assessment of the below systems and technologies:
Remote authentication - VPN Gateway, Remote Desktop Gateway
Email - Hybrid on-prem Exchange and Exchange Online (O365)
Database servers (customer data) - Hybrid on-prem and on AWS, non-internet-facing
Web applications (online banking) - Hosted on AWS, internet-facing
Electronic data interchange (EDI) for purchasing, inventory management, warehousing, and shipping/receiving
Money movement systems that are used by the business to move its money around such as wires, ACH transfers, digital payment networks (Zelle, Venmo, PayPal), and check requests. - Hybrid on-prem and on AWS, non-internet facing.
For each of these categories, conduct research and identify the specific threat and vulnerability and, with internal content as the priority, describe the impact of malicious attacks, lack of knowledge, and accidental loss:
1. primary threats associated with the content found on each system.
2. the most common vulnerabilities exploited by those threats in each system.
3. the overall risk each presents to the organization. Select one primary mitigation method for each area specifically to reduce the risk you have identified.
Your findings should create a logical evaluation that can aid further planning and mitigations, using prioritized risks. When making your decisions as to what the best pathway forward is, consider the interaction of suppliers, customers, employees, service providers, outsourced employees, and other links established by your organization.
Length: 5 to 7-page paper, excluding title and reference pages.
References: Include a minimum of 2 scholarly references in addition to those used in the course resources.