Module 6: A Case for Back-up & Recovery
For this assignment, you will need to review the Case Study presented and outline a contingency plan that addresses possible security threats and breaches, provides a strategy to minimize the disruption to hospital operations while protecting patient information.
Expand AllPanels Collapse AllPanels
Case Study
DeVry Hospital, a 200-bed acute-care facility, has been encountering security incidents involving a ransomware attack, in addition to a major breach of patient records. The Chief Privacy & Security Officer is requesting a contingency plan that will minimize the potential for security threats and provide for continuity of the necessary hospital operations to care for patients.
Action Plan
As a member of the security team, you have been asked to outline a contingency plan to counteract the identified ransomware attacks, data breaches and prepare the hospital for natural disasters and potential system failures. You plan should include clear procedures for mitigating the security breaches.
Steps you will complete the following as part of your proposed contingency plan:
1. Provide a risk assessment that identifies and prioritizes potential security threats.
2. Propose possible strategies to prevent security incidents. This should involve system updates, possible employee training that may be needed and security protocols.
3. Outline a procedure for regular data backups with a clear data recovery plan in case of a system crash.
4. Recommend a process for completing a post-incident review to ensure a thorough investigation is completed to identify any potential gaps in the existing contingency plan.
Your deliverable method can be either in the form of a half-page to full page proposal or PowerPoint slides that outline each of the strategies you are proposing with an action plan for implementing them. For PowerPoint slides, the slides should outline your key points/recommendations and utilize the Notes section under your slides to provide complete sentences for your report as if you were presenting to a board for approval to implement.
Note: If you utilize your textbook or any references to support your recommendations, provide a reference list.
This assignment utilizes TurnItIn, which reviews citations, plagiarism, and artificial intelligence (AI) usage.
Action
Select the Start Assignment button to begin.
Once you have uploaded your file, select Submit Assignment.
Rubric
M6 A Case for Back-up & Recovery
M6 A Case for Back-up & Recovery
|
Criteria
|
Ratings
|
Pts
|
This criterion is linked to a Learning OutcomeParameters
Parameters
Paper Option
-Uses standard double-spacing without extra spaces between bullets or paragraphs
-Minimum length 1/2 page, maximum length 1 page
-Free of grammatical & spelling errors
-Uses APA in-text citations and reference list IF applicable
PowerPoint Option
-No more than 5 bullets per slide
-Keep slides uncluttered so easy to follow
-Notes Section of slides should contain a detailed outline of what slide is presenting (speaker notes)
-Free of grammatical & spelling errors
-Uses APA in-text citations and reference list on a reference slide IF applicable
|
5 pts
Meets or Exceeds
Student submission clearly encompasses all of PowerPoint presentation parameters -Minimum of 5 content slides, Maximum of 8 content slides -Includes a title slide -Includes a reference slide if needed -Presentation developed from perspective as if being presented to the board -No more than 5 bullets per slide -Keep slides uncluttered so easy to follow -Includes use of graphical representations to give visual emphasis & credibility to presentation -Notes Section of slides should contain a detailed outline of what slide is presenting (speaker notes) -Free of grammatical & spelling errors -Uses APA in-text citations and reference list on a reference slide IF applicable
|
3 pts
In Progress
Student submission clearly encompasses all paper or PowerPoint parameters -Free of grammatical & spelling errors -Uses APA in-text citations and reference list IF applicable
|
1 pts
Little Evidence
Student submission does not clearly meet the paper or PowerPoint parameters -Has 4 or more grammatical & spelling errors -does not use APA in-text citations and reference list IF applicable
|
0 pts
No Evidence
Student submission clearly does not meet the required Parameters
|
|
5 pts
|
This criterion is linked to a Learning OutcomeRisk Assessment
Risk Assessment
-Provides risk assessment that identifies potential security threats
-Includes prioritization of potential security threats
|
7 pts
Meets or Exceeds
Student submission provides clear identification of potential security threats through risk assessment and includes prioritization of potential security threats
|
5 pts
In Progress
Student submission mostly provides identification of potential security threats through risk assessment and inclusion of prioritization of potential security threats – may be missing pertinent information
|
2 pts
Little Evidence
Student submission is off topic for control mechanisms or does not identify potential security threats through risk assessment and inclusion of prioritization of potential security threats
|
0 pts
No Evidence
Student submission does not clearly meet the expectations for identifying potential security threats through risk assessment and inclusion of prioritization of potential security threats
|
|
7 pts
|
This criterion is linked to a Learning OutcomeSecurity Incident Prevention
Security Incident Prevention
Provides strategies to prevent potential security incidents that includes consideration of
-system updates
-possible employee training
-needed security protocols
CO6
|
7 pts
Meets or Exceeds
Student submission on Security Incident Prevention clearly identifies strategies to prevent potential security incidents that includes consideration of -system updates -possible employee training -needed security protocols
|
5 pts
In Progress
Student submission on Security Incidence Prevention mostly identifies strategies to prevent potential security incidents that includes consideration of -system updates -possible employee training -needed security protocols
|
2 pts
Little Evidence
Student submission on Security Incidence Prevention does not consider all of these factors -system updates -possible employee training -needed security protocols
|
0 pts
No Evidence
Student submission on Security Incidence Prevention clearly does not meet expectations or nothing submitted
|
|
7 pts
|
This criterion is linked to a Learning OutcomeTraining Programs
Training Programs
-Findings of review on training program deficiencies encompasses assessment on proper use/protocols on electronic health record and HIPAA compliance
CO6
|
7 pts
Meets or Exceeds
Student submission on Training Programs clearly addresses findings of review on training program deficiencies and encompasses assessment on proper use/protocols on electronic health record and HIPAA compliance
|
5 pts
In Progress
Student submission on Training Programs mostly addresses findings of review on training program deficiencies and encompasses assessment on proper use/protocols on electronic health record and HIPAA compliance but may be lacking details
|
2 pts
Little Evidence
Student submission on Training Programs is off topic or does not clearly address findings of a review covering training program deficiencies relating to use/protocols on electronic health record and/or HIPAA compliance
|
0 pts
No Evidence
Student submission clearly does not meet expectations on addressing training program review findings or nothing submitted
|
|
7 pts
|
This criterion is linked to a Learning OutcomePost Incident Review Process
Post Incident Review Process
Proposes a process to follow post-incident review that ensures an investigation that identifies any gaps in current contingency plan
CO6
|
9 pts
Meets or Exceeds
Student submission of Post Incident Review clearly proposes a process to follow post-incident review that ensures an investigation that identifies any gaps in current contingency plan
|
6 pts
In Progress
Student submission of Post Incident Review mostly identifies a process to follow post-incident review that ensures an investigation that identifies any gaps in current contingency plan
|
3 pts
Little Evidence
Student submission of Post Incident Review is off topic or does not clearly give a proposed process to follow post-incident review that ensures an investigation that identifies any gaps in current contingency plan
|
0 pts
No Evidence
Student submission does not clearly meet expectations to provide proposed process to follow post-incident review
|
|
9 pts
|
Total Points: 35
|