Risk management plan – single risk Company name: MyHealth.
Verified
Added on 2023/01/17
|1
|339
|66
AI Summary
Contribute Materials
Your contribution can guide someone’s learning journey. Share your
documents today.
Risk management plan – single risk Company name:MyHealthCompleted by:Student name Work area:Cybersecurity managementDate completed:date Hazard identification Hazard:Unauthorized access of database server Risk assessment What harm could the hazard cause? Company can loss their reputation in the market and it is also risky for treatment of patients. Database is having payment details. What is the likelihood of this happening Because of open access to the server room of all the staff, it can cause to the hacking of server. It increases likelihood of this threat. Existing control measure 1.Restrict entry for all the staff 2.IT people can entry in the room with permission 3.Server and other devices will be in physical security Consequence$500,000 Likelihood0.5 OutcomeAnnualized Loss Expectancy (ALE) = 250,000 Control measures Detective controlsRestrict entry of all the staff Secure and strong password with the help of password creator tools Corrective controlsUpdate antivirus of all the systems PreventiveInstall network firewall to secure network Administrative Provide different access level based on the requirements to all staff members Implementation Associated activitiesResources required Person(s) responsibleSign off and date Installing a firewallFirewall hardware Chief information security officer (CISO)’s name CISO signature and date Updating antivirusAntivirus definitionAllocated personCISO signature and date Update operating systemsWindows 10 Chief information security officer (CISO)’s name CISO signature and date REVIEW Scheduled review date:// Are the control measures in place? Yes/no based on the student assumption Are the controls eliminating/minimising the risk? Yes/no based on the student assumption Are there any new problems with the risk? Explain if the existing risk exceeds t the acceptable level of risk in the company Adapted from: Workplace Health and Safety Queensland – How to manage work health and safety risks code of practice. 2011