MonsterMed Inc. (MMI) is an online pharmaceutical firm. MMI has a small systems staff that designs and
Question:
MonsterMed Inc. (MMI) is an online pharmaceutical firm. MMI has a small systems staff that designs and writes MMFs customized software. Until recently, MMI’s transaction data were transmitted to a service bureau for processing on its hardware. MMI has experienced significant sales growth as the cost of prescription drugs has increased and medical insurance companies have been tightening reimbursements in order to restrain premium cost increases. As a result of these increased sales, MMI has purchased its own computer hardware. The computer center is installed on the ground floor of its two-story headquarters building. It is behind large plate glass win¬ dows so that the state-of-the-art computer center can be displayed as a measure of the company’s success and to attract customer and investor attention. The computer area is equipped with halon-gas fire suppression equipment and an uninterruptible power supply system.
MMI has hired a small computer operations staff to operate this computer center. To handle MMI’s current level of business, the operations staff works a two-shift schedule, five days per week. MMFs systems and programming staff, now located in the same building, has access to the computer center and can test new programs and program changes when the operations staff is not available. Since the systems and programming staff is small and the work demands have increased, systems and pro¬ gramming documentation is developed only when time is available. Backups occur periodically as time allows. MMI backs up its programs and data files, storing them at an off-site location.
Unfortunately, due to several days of heavy rains, MMFs building recently expe¬ rienced serious flooding that reached several feet into the first-floor level and destroyed not only the computer hardware but also the data and program files that were on-site.
Required
a. Describe at least four computer security weaknesses that existed at MonsterMed Inc. prior to the flood occurrence.
b. Describe at least five components that should be incorporated in a formal disaster recovery plan in order that MMI can become operational within 72 hours after a disaster affects its computer operations capability.
Step by Step Answer: