Our Services

Get 15% Discount on your First Order

[rank_math_breadcrumb]

Assign 2 of CG

Follow the attach information to complete this work. Make sure it aligns with the Rubric.

Unit 2 Assignment Directions:

Risk-Assessment Strategy

Purpose

In this assignment, you will detail the risk-assessment plan and strategy for your organization that you described in your discussion post. You have demonstrated that you understand their core business functions and mission. Your risk assessment should be tailored to that understanding. If you implement the risk-management controls recommended by NIST, another standards body, or a trade association for your industry, you will be demonstrating compliance with government requirements. This means that if there is a breach, your legal office can provide a written justification that maps your compliance to your direct business services. This will also support any insurance claims and help to maintain your business reputation.

Directions

Write a detailed overview and analysis of the fundamentals of risk management in cybersecurity for your organization that you described in your discussion post. You may choose one of the following two options for formatting your response (see details below):

· Option A: A 4- to 6-page paper 
OR

· Option B: A matrix (sample provided below) and a 2- to 3-page narrative

Regardless of which format you choose, be sure to address all the following elements:

1.
Write a substantive executive summary that includes the following:

a. A brief statement on the purpose and scope of the RA

b. Your focus on the current organizational assessment

c. Your risk-mitigation and management strategy

d. Cited references to authorities that show the organization’s compliance with government requirements, industry best practices (NIST), or other standards

2.
Assess the cybersecurity posture of your chosen organization. Be sure to include the following:

a. Describe your organization’s business goals, mission, objectives, and how the requirements would support them.

b. Use the implementation tiers in NIST to assess your organization’s current situation.

c. List vulnerabilities, countermeasures, and recommendations for improvement.

3.
Apply the NIST RMF framework:

a. Explain in more detail how to use NIST 800-53 (rev.5), NIST 800-30, and the new NIST 2.0 to create a comprehensive strategy.

b. Explain what actions you would take to align your business strategy with the recommended NIST best practices.

c. Clearly map the business objectives and goals to a cybersecurity plan. Include all the following key measures:

i. Prepare the organization.

ii. Categorize system and information.

iii. Select a range of 4–6 NIST SP 800-53 controls.

iv. Implement the controls and document how controls were deployed.

v. Assess whether the controls are in place, operating as intended, and producing the desired outcomes.

vi. Authorize risk-based decision-making.

vii. Continuously monitor implementation and risks to the system.

4.
Evidence of skills: Demonstrate your knowledge of risk-assessment protocols as well as legal and regulatory compliance.

5.
Write the paper with an organized, logical flow of information. Cite authoritative sources sufficiently to show that your analysis is based on the resources provided or other documents you find through your research. Please use a consistent citation style.

Executive Summary Features

Here are some ideas for what to include in your executive summary. A CEO should be able to use your summary for decision-making purposes. An executive summary includes a brief statement of the issue, which helps the executive understand the topic (risk mitigation and management).

As stated in the directions, cite the authorities you are using to show compliance with government requirements, industry best practices (e.g., NIST), or other standards. To analyze the importance of these requirements and best practices, one approach would be to follow the suggestions below.

Explain briefly how the templates and their rationale provide assurances to the CEO that these requirements reduce the organization’s cybersecurity risk. One way to do this is to cite a specific requirement as an example and explain how it is applied. Then you may also want to talk briefly about a technological solution you are using to assist you in this effort. You can then list some of the vulnerabilities your organization has in the system and explain how you will address them, Finally, you could discuss how you will make sure that you are ensuring compliance (e.g., continuous monitoring, establishing a training program that requires quarterly testing, or some other methods that demonstrate active participation).

To remind yourself how to cite references, visit the Library’s 
APA Document Formatting (7th Edition) and 
APA 7th Edition Citation Examples.

Format

Click the “+” to expand each section below.

Suggested Outline for Option A: Paper

Suggested Outline for Option B: Narrative and Matrix

Submission

· Review the Unit 2 Risk-Assessment Strategy Rubric to understand how you will be assessed on this assignment.

image4.png

image5.png

image6.png

image7.png

image8.png

image1.png

image2.png

image3.png

Share This Post

Email
WhatsApp
Facebook
Twitter
LinkedIn
Pinterest
Reddit

Order a Similar Paper and get 15% Discount on your First Order

Related Questions

Network Threats

  Questions: Below is a list of common network attacks: Distributed Denial of Service (DDoS) DNS poisoning ARP poisoning Domain hijacking MAC flooding MAC cloning Man-in-the-Middle Explain two of these network attacks and discuss methods/techniques for protecting the network against them.

Best Practices for Role-Based Privilege Management in Databases

  Research the best practices for managing and securing role-based privileges in databases and address the following questions in your discussion post:  What are the key challenges in managing role-based privileges, and how do they impact database security? Can you provide a real-world scenario where poor role-based privilege management led

Computer Science Cloud Computing assignment

Please see attachment for details 4 [ Note: To complete this template, replace the bracketed text with your own content. Remove this note before you submit your paper.] Cloud Computing Evaluation Paper 1 Cloud Computing [Differentiate between cloud computing models and their uses. What are the different types of deployment

Computer Science- Python Python Programming Assignment

Computer Science Python Programming Lab assignment help. Design a Python program that calculates a credit card customer’s minimum payment based on their balance. Please use If Else and elif statements in your code. You must add comments in your code. Please round the minimum payment to two decimal places using

Blockchain Application

I need help with my coursework project. Let me know if you need any help from me.  Lab 2: Blockchain-Based Academic Credentials Lab Lastname: ______________ Firstname:________________ 1. Overview AETHELRED UNIVERSITY Registrar’s Office wants to start issuing a digital transcripts and diploma for graduating students. You are called to build the

LOREM, IPSUM

The ability to develop a risk register is a skill needed by all cybersecurity leaders when assessing cybersecurity risks. A risk register provides a detailed listing of known risks as well as quantitative or qualitative assessments of those risks, resulting in the prioritization of action.

Virtual LANs

  Questions: A VLAN allows different devices to be connected virtually to each other as if they were in a LAN sharing a single broadcast domain. 1. Why a network engineer would want to deploy VLANs? 2. How do VLANs improve network security?

compliance and rules to follow in cybersecurity.

Follow the attached instructions to complete this work. Note: Make sure to follows rubric or aligns with Rubric. Unit 8 Assignment Directions: Case Study Review the following hypothetical case study. Consider the big-picture ideas and the specific concerns. Make use of the key terms and concepts from the readings in

Discussion on data ( computer science)

Follow the attached direction to complete this work Unit 7 Discussion   Overview Consider this scenario: PQR Corporation provides facial recognition technology to customers. Its products include customer access to consumer electronics as well as mass surveillance capabilities through networked camera systems. While operating legally, PQR has maintained a low

Computer Science – Machine Learning Python Programming Assignment

Assignment Help. Please don’t forget to add comments in the code Page 1 of 3 NorQuest College – CMPT 1011: Lab Assignment 5 CMPT 1011: Introduction to Computing Lab Assignment 2: Variables, mathematical operations and data types Value This coding challenge is worth 3% of your final grade. Background In

Public safety Communications

Subscribe The Communications and Cyber Resiliency Toolkit provides guidance for establishing resiliency measures, public safety communications can better withstand potential disruptions to service. This toolkit, developed by CISA, describes networks and systems critical to successful communication and cyber resiliency and possible threats while providing many resources and additional links for

Case Study 4 o Data (computer)

Follow the attached instructions to complete this work Unit 4 Case Study Directions Review the following case study. Consider both the big-picture ideas and the specific concerns. Make use of the key terms and concepts from the readings in your written responses to the questions below. The case study paper

Discussion 5 and 6

Follow  the attached instructions to complete this work Unit 5 Discussion   Overview In this discussion, you will be considering the emphasis on aspects such as privacy and safety. You will reflect on the significance of the legal concerns and goals of public-private partnerships to address cybersecurity. You will also

SQL injection

Hey! ????  I need an expert in SQL injection, DDOS attack, Code injection attack, XSS attack! To talk further please contact me on discord at mara411 so we can talk more freely and then I will hire you on here! Thanks ???? 

Free CAD, FeniCS or paraview

I have attached the picture and sample work too, I need work as like sampl, but not the copypasted Make sure you can ask me multiple questions but not dont do rubbish work

database

2. Final Assignment – equivalent to 4,000 words The final module mark is based on two deliverables focused on the CarNow case study described below. – 50% of the final mark a. An advisory report – 50 % of the final mark Includes 5% (of the module grade) given for

Computer

Documentation Tabula Insurance Agency ENTER AND UPDATE COMPANY DATA Author: Ashanti Joyner Note: Do not edit this sheet. If your name does not appear in cell B6, please download a new copy of the file from the SAM website. Personnel Tabula Insurance Agency Personnel: April 4-10, 2024 Employee Name Salary

Computer class

All information is below Toronto converted a declining part of the city into a vibrant neighborhood using the smart city 1.0 approach when a local technology company introduced electric shuttle buses to replace private cars and intelligent traffic lights to regulate the flow of pedestrians, bicycles, and vehicles. From Frankl,