Description
CYB-300: Risk Management and Information Technology Security
Application of Risk Management
As discussed in this workshop, after IT professionals identify threat/vulnerability pairs and estimate the likelihood of their occurrence, IT management must decide which risk management techniques are appropriate to manage these risks. IT managers then present this information to senior management. The role of the senior management is to allocate resources, specifically money and employees, to prepare for and respond to identified threats and vulnerabilities appropriately.
This task allows you to fulfill the role of an IT manager in a small business tasked with determining appropriate risk management techniques for identified threats and vulnerabilities and to make related recommendations to senior management.
Resources
- Textbook: Managing Risk in Information Systems (Chapters 1-3)
Background Information
Scenario:
YieldMore is a small agricultural company that produces and sells fertilizer products. The company operates through its headquarters in a small town in Indiana. Outside its headquarters, there are two large production facilitiesone in Nebraska and one in Oklahoma. Furthermore, YieldMore employs sales force personnel in every state in the U.S. to serve its customers locally.
The company has three servers located at its headquartersActive Directory Server, a Linux application server, and an Oracle database server. The application server hosts YieldMores primary software application, which is proprietary program managing inventory, sales, supply-chain, and customer information. The database server manages all data stored locally with direct attached storage.
All three major sites use Ethernet cabled local area networks (LANs) to connect the users Windows Vista workstations via industry standard, managed switches.
The remote production facilities connect to headquarters via routers T-1 (1.54 mbps telecomm circuit) LAN connections provided by an external Internet service providers (ISP) and share an Internet connection through a firewall at headquarters.
Individual sales personnel throughout the country connect to YieldMores network via virtual private network (VPN) software through their individual Internet connections, typically in a home office.
Instructions
- Assume the role of an IT manager assigned by YieldMores senior management to conduct the following risk management tasks:
- Identify, analyze, and explain several (at least five) likely threat/vulnerability pairs and their likelihood of occurrence in this scenario.
- For each of the threat/vulnerabilities you identify, determine which of the six risk management techniques is appropriate for each risk explained in Task 1.
- Justify your reasoning for each chosen management technique. Prepare a brief report or presentation of your findings for senior management to review.