Question
This part of the project is a continuation of the Project 1, Part 1 where you prepared RA plan and a risk mitigation plan for
This part of the project is a continuation of the Project 1, Part 1 where you prepared RA plan and a risk mitigation plan for the Health Network. Senior management at Health Network decided that the risk manager and his/her team should continue and develop a RA plan based on inputs provided by the team in earlier project deliverables. Management has also allocated funds for a risk mitigation plan and a BIA plan. Because of the importance of risk management to the organization, senior management is committed to and supportive of the project to develop a new plan. You have been assigned to develop this new plan.
- Task 1: Introduction and Business Impact Analysis Plan: You have been assigned the task of making a final Risk Assessment plan, a final Risk Mitigation Plan, and a Business Impact Analysis Plan. In order to create your BIA plan, you will need to do the following:
- Research BIAs
- Develop a BIA plan for Health Network that focuses on the data center. The BIA should identify:
- Critical business functions
- Critical resources
- Maximum acceptable outage (MAO) and impact
- Recovery point objective (RPO) and recovery time objective (RTO).
- Create a professional report detailing the information in your final Risk Assessment plan, your final Risk Mitigation Plan, and your Business Impact Analysis Plan.
- Task 2: Business Continuity Plan
- As mentioned above, Senior Management has allocated funds to pay for a Business Continuity Plan to be created. You have been assigned to develop this new plan, and you need to take the following information into consideration:
- Winter storms on the East Coast have affected the ability of Health Network employees to reach the Arlington offices in a safe and timely manner. However, no BCP plan currently exists to address corporate operations. The Arlington office is the primary location for business units, such as Finance, Legal, and Customer Support. Some of the corporate systems, such as the payroll and accounting applications, are located only in the corporate offices. Each corporate location is able to access the other two, and remote virtual private networks (VPNs) exist between each production data center and the corporate locations.
- The corporate systems are not currently being backed up and should be addressed in the new plan.
- You need to create a BCP that could recover business operations while efforts are ongoing to restart previous operations.
- The BCP should also include some details regarding how the BCP will be tested.
- Do not forget to develop a testing plan for your team's Business Continuity Plan.
- Make a professional report detailing the information in Business Continuity Plan. You may use or repurpose a BCP template you find online, but make sure to include a description of how you would test the plan.
- As mentioned above, Senior Management has allocated funds to pay for a Business Continuity Plan to be created. You have been assigned to develop this new plan, and you need to take the following information into consideration:
- Task 3: Disaster Recovery Plan:Your project on risk management up to this point has been reviewed and appreciated by the senior management.
- They now want you to develop a Disaster Recovery Plan in order to overcome any mishaps that might occur in the future.
- Use your research on NIST templates to develop your DRP plan for Health Network.
- Make sure you develop a Disaster Recovery Plan that could recover business operations while efforts are ongoing to restart pervious operations?
- Make sure to completely fill out the template found in your NIST research.
- Task 4: Computer Incident Response Team Plan: By now you should have developed a Risk Assessment Plan, a Risk Mitigation Plan, a Business Impact Analysis, a Business Continuity Plan, and a Disaster Recovery Plan.
- In this final Task, you will create a Computer Incident Response Team Plan for Health Network after having learned the concepts of CIRT. Remember that the Health Network headquarters (HQ) handles all incidents, so the plan will have its roots at HQ.
- After creating the CIRT plan you will need to compile the completed set of your risk management plans together for final submission of the project.
- Make sure to incorporate your instructor's feedback in your final set of risk management plans.
Step by Step Solution
There are 3 Steps involved in it
Step: 1
Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started