Reference no: EM132381476
ICTSAS505 - Assessment Task-1 Case Study
Unit Code ICTSAS505
Unit Name Review & Update Disaster Recovery &Contingency Plans
Rare problem blamed for Glasgow health board IT crash
A "rare corruption" in a vital computer programme has been blamed for a systems crash which hit hospital appointments at Scotland's largest health board. An independent investigation into the NHS Greater Glasgow and Clyde (GGC) crash, however, could not establish "the exact root cause of the failure". The report makes eight recommendations for improvements. The systems crash, between 1 and 3 October, resulted in 709 patients having hospital appointments postponed. The independent investigation into the system failure was commissioned by NHS GGC and the Scottish government.
It confirmed that the source of the problem related to a rare corruption in a programme known as Active Directory. Active Directory is a commonly used part of IT infrastructure which manages how users are given access to the various services they have permissions for.
Information Technology Security Policy
Purpose of the Policy
This policy provides guidelines for the protection and use of information technology assets and resources within the business to ensure integrity, confidentiality and availability of data and assets.
Procedures: Physical Security
For all access to the servers, mainframes and other network assets, the area must be secured with adequate ventilation and appropriate.
It will be the responsibility of the Administration Staff to ensure that this requirement is followed at all times. Any employee becoming aware of a breach to this security requirement is obliged to notify Administration Manager immediately.
Computer Access
All Administration Staff are required to use their appropriate usernames and passwords to ensure customer information is kept safely at all times. In the event of loss or damage, IT Service Desk will assess the security measures undertaken to determine if the employee will be required to reimburse the business for the loss or damage.
If there is a system failure then the Administration Staff are required to immediately contact the Administration Manager on duty to escalate the issue to the IT Service Desk Manager. Failure to do so will incur penalties.
Information Security
All Patient information is sensitive and is to be backed-up. It is the responsibility of Administration Manager is to ensure that data back-ups are conducted nightly and the backed up data is kept offsite and a hardcopy stored in the compactus. All technology that has internet access must have anti-virus software installed. All
information used within the business is to adhere to the privacy laws and the business's confidentiality requirements. Any employee breaching this will be severe.
Technology Access
Every employee will be issued with a unique identification code to access the business technology and will be required to set a password for access every month. Passwords are not to be shared with any staff member within the hospital. The Administration Manager is responsible for the issuing of the identification code and initial password for all employees. Where a staff member forgets the password or is ‘locked out' after three attempts, then the IT Service Desk is authorised to reissue a new initial password that will be required to be changed when the employee logs in using the new initial password.
Assessment Description
Please answer all questions in this assessment. This assessment will have a set scenario based questions. This assessment is based on a case study relating to Glasgow Health Board.
Part A - Policy Change
The Glasgow health board requires an update to their IT policy due to this failure. Please add the following sections in the policy documentation that will assist in the recovery process:
• Everyday business (1-2 paragraphs)
• Failures or disasters (1-2 paragraphs)
Part B - Determining Strategies
Before you can generate a recovery plan, you'll need to perform a risk assessment (RA) and/or business impact analysis (BIA) to identify the IT services that support the organization's critical business activities. Then, you'll need to establish recovery time objectives (RTOs) and recovery point objectives (RPOs).
Assessing the Glasgow health board IT crash scenario and the example of a determining strategy table, use the following table to assist with the Glasgow health board:
Key Requirements
• Complete all sections of Part A and B
• Add 2 new sections in the policy documentation
• Complete the strategy table
Attachment:- Review and Update Disaster Recovery &Contingency Plans.rar