30 May Identifying Potential Risk, Response, and Recovery
In the previous assignment, a videogame development company recently hired you as an Information Security Engineer. After viewing a growing number of reports detailing malicious activity, the CIO requested that you draft a report in which you identify potential malicious attacks and threats specific to your organization. She asked you to include a brief explanation of each item and the potential impact it could have on the organization.
After reviewing your report, the CIO requests that you develop a follow-up plan detailing a strategy for addressing all risks (i.e., risk mitigation, risk assignment, risk acceptance, or risk avoidance) identified in the previous assignment. Further, your plan should identify controls (i.e., administrative, preventative, detective, and corrective) that the company will use to mitigate each risk previously identified.
Write a four to five (4-5) page paper in which you:
1. For each of the three (3) or more malicious attacks and / or threats that you identified in the previous assignment, choose a strategy for addressing the associated risk (i.e., risk mitigation, risk assignment, risk acceptance, or risk avoidance). Explain your rationale.
2. For each of the three (3) or more malicious attacks and / or threats identified in the previous assignment, develop potential controls (i.e., administrative, preventative, detective, and corrective) that the company could use to mitigate each associated risk.
3. Explain in detail why you believe the risk management, control identification, and selection processes are so important, specifically in this organization.
4. Draft a one (1) page Executive Summary that details your strategies and recommendations to the CIO (Note: The Executive Summary is included in the assignment’s length requirements).
5. Use at least three (3) quality resources in this assignment (no more than 2-3 years old) from material outside the textbook. Note: Wikipedia and similar Websites do not qualify as quality resources.
Your assignment must follow these formatting requirements:
· Be typed, double spaced, using Times New Roman font (size 12), with one-inch margins on all sides; references must follow APA or school-specific format. Check with your professor for any additional instructions.
· Include a cover page containing the title of the assignment, the student’s name, the professor’s name, the course title, and the date. The cover page and the reference page are not included in the required page length.
The specific course learning outcomes associated with this assignment are:
· Explain the concepts of information systems security as applied to an IT infrastructure.
· Describe the principles of risk management, common response techniques, and issues related to recovery of IT systems.
· Describe how malicious attacks, threats, and vulnerabilities impact an IT infrastructure.
· Explain the means attackers use to compromise systems and networks, and defenses used by organizations.
· Use technology and information resources to research issues in information systems security.
· Write clearly and concisely about network security topics using proper writing mechanics and technical style conventions.
| Criteria |
Unacceptable Below 60% F |
Meets Minimum Expectations
60-69% D |
Fair 70-79% C |
Proficient 80-89% B |
Exemplary 90-100% A |
| 1. For each of the three (3) or more malicious attacks and / or threats that you identified in Assignment 1, choose a strategy for addressing the associated risk (i.e., risk mitigation, risk assignment, risk acceptance, or risk avoidance). Explain your rationale.
Weight: 20% |
Did not submit or incompletely chose a strategyfor addressing the associated risk (i.e., risk mitigation, risk assignment, risk acceptance, or risk avoidance)for each of the three (3) or more malicious attacks and / or threats that you identified in Assignment 1. Did not submit or incompletely explained your rationale. | Insufficiently chose a strategyfor addressing the associated risk (i.e., risk mitigation, risk assignment, risk acceptance, or risk avoidance)for each of the three (3) or more malicious attacks and / or threats that you identified in Assignment 1. Insufficiently explained your rationale. | Partially chose a strategy for addressing the associated risk (i.e., risk mitigation, risk assignment, risk acceptance, or risk avoidance)for each of the three (3) or more malicious attacks and / or threats that you identified in Assignment 1. Partially explained your rationale. | Satisfactorily chose a strategyfor addressing the associated risk (i.e., risk mitigation, risk assignment, risk acceptance, or risk avoidance)for each of the three (3) or more malicious attacks and / or threats that you identified in Assignment 1. Satisfactorily explained your rationale. | Thoroughly chose a strategy for addressing the associated risk (i.e., risk mitigation, risk assignment, risk acceptance, or risk avoidance)for each of the three (3) or more malicious attacks and / or threats that you identified in Assignment 1. Thoroughly explained your rationale. |
| 2. For each of the three (3) or more malicious attacks and / or threats identified in Assignment 1, develop potential controls (i.e., administrative, preventative, detective, and corrective) that the company could use to mitigate each associated risk. Weight: 20% |
Did not submit or incompletely developedpotential controls (i.e., administrative, preventative, detective, and corrective) that the company could use to mitigate each associated riskfor each of the three (3) or more malicious attacks and / or threats identified in Assignment 1. | Insufficiently developedpotential controls (i.e., administrative, preventative, detective, and corrective) that the company could use to mitigate each associated riskfor each of the three (3) or more malicious attacks and / or threats identified in Assignment 1. | Partially developedpotential controls (i.e., administrative, preventative, detective, and corrective) that the company could use to mitigate each associated riskfor each of the three (3) or more malicious attacks and / or threats identified in Assignment 1. | Satisfactorily developedpotential controls (i.e., administrative, preventative, detective, and corrective) that the company could use to mitigate each associated riskfor each of the three (3) or more malicious attacks and / or threats identified in Assignment 1. | Thoroughly developedpotential controls (i.e., administrative, preventative, detective, and corrective) that the company could use to mitigate each associated riskfor each of the three (3) or more malicious attacks and / or threats identified in Assignment 1. |
| 3. Explain in detail why you believe the risk management, control identification, and selection processes are so important, specifically in this organization.
Weight: 20% |
Did not submit or incompletely explained in detail why you believe the risk management, control identification, and selection processes are so important, specifically in this organization. | Insufficiently explained in detail why you believe the risk management, control identification, and selection processes are so important, specifically in this organization. | Partially explained in detail why you believe the risk management, control identification, and selection processes are so important, specifically in this organization. | Satisfactorily explained in detail why you believe the risk management, control identification, and selection processes are so important, specifically in this organization. | Thoroughly explained in detail why you believe the risk management, control identification, and selection processes are so important, specifically in this organization. |
| 4. Draft a one (1) page Executive Summary that details your strategies and recommendations to the CIO. Weight: 25% |
Did not submit or incompletely drafted a one (1) page Executive Summary that details your strategies and recommendations to the CIO. | Insufficiently drafted a one (1) page Executive Summary that details your strategies and recommendations to the CIO. | Partially drafted a one (1) page Executive Summary that details your strategies and recommendations to the CIO. | Satisfactorily drafted a one (1) page Executive Summary that details your strategies and recommendations to the CIO. | Thoroughly drafted a one (1) page Executive Summary that details your strategies and recommendations to the CIO. |
| 5. 3 references
Weight: 5% |
No references provided | Does not meet the required number of references; all references poor quality choices. | Does not meet the required number of references; some references poor quality choices. | Meets number of required references; all references high quality choices. | Exceeds number of required references; all references high quality choices. |
| 6. Clarity, writing mechanics, and formatting requirements
Weight: 10% |
More than 8 errors present | 7-8 errors present | 5-6 errors present | 3-4 errors present | 0-2 errors present |
Our website has a team of professional writers who can help you write any of your homework. They will write your papers from scratch. We also have a team of editors just to make sure all papers are of HIGH QUALITY & PLAGIARISM FREE. To make an Order you only need to click Ask A Question and we will direct you to our Order Page at WriteDemy. Then fill Our Order Form with all your assignment instructions. Select your deadline and pay for your paper. You will get it few hours before your set deadline.
Fill in all the assignment paper details that are required in the order form with the standard information being the page count, deadline, academic level and type of paper. It is advisable to have this information at hand so that you can quickly fill in the necessary information needed in the form for the essay writer to be immediately assigned to your writing project. Make payment for the custom essay order to enable us to assign a suitable writer to your order. Payments are made through Paypal on a secured billing page. Finally, sit back and relax.
About Writedemy
We are a professional paper writing website. If you have searched a question and bumped into our website just know you are in the right place to get help in your coursework. We offer HIGH QUALITY & PLAGIARISM FREE Papers.
How It Works
To make an Order you only need to click on “Order Now” and we will direct you to our Order Page. Fill Our Order Form with all your assignment instructions. Select your deadline and pay for your paper. You will get it few hours before your set deadline.
Are there Discounts?
All new clients are eligible for 20% off in their first Order. Our payment method is safe and secure.
