Reference no: EM133964917 , Length: Word Count:2500
IS Governance and Risk
Part A: The Case Study - "Titan Health Analytics (THA)"
Company Profile:
THA is a rapidly growing Australian firm that provides data analytics for private hospitals. Over the last 18 months, they transitioned from a local server-based model to a multi-cloud environment (AWS and Azure).
The Problems:
Framework Vacuum: THA has no formal IT Governance framework. Decisions are made "ad hoc" by the CTO, often bypassing the Board of Directors.
Compliance Crisis: Since they handle sensitive medical records, they are subject to the Privacy Act 1988 (Australia). However, a recent internal "spot check" found that data access logs are not being monitored, and "Shadow IT" (unauthorized apps) is rampant in the marketing department.
Risk Management: There is no centralized Risk Register. Last month, a misconfigured cloud bucket exposed 5,000 non-medical client records for three days before it was discovered. Your reliable and affordable assignment help starts today!
Operational Friction: The IT department is viewed as a "bottleneck" rather than a strategic partner, leading to high staff turnover in the security team.
Part B: Specific Task Requirements
Students must act as an External Governance Consultant and produce a 2,500-word Proposal addressed to the Board of THA.
Framework Recommendation
Critically evaluate two frameworks (e.g., COBIT 2019 and ISO/IEC 38500).
Compare their strengths regarding THA's cloud-based model and recommend which one should be adopted as the primary governance structure.
Risk Assessment & Matrix
Identify four distinct risks (Strategic, Operational, Financial, and Compliance). For each risk, students must:
Assess the Likelihood and Impact.
Map them onto a 5 x 5 Risk Heat Map.
Propose a mitigation strategy (e.g., implementing specific NIST controls).
Information Compliance & Audit Plan
THA is currently failing its data governance obligations. Students must:
Propose a Data Governance Strategy (mentioning roles like Data Stewards and Owners).
Outline a High-Level Audit Program (Week 8 topic) to ensure ongoing compliance with health data regulations.
Scholarly Approach
Students must support their arguments using at least eight (8) peer-reviewed sources. These should justify why certain frameworks are superior for healthcare analytics firms or the impact of poor IT governance on organizational performance.