Our Services

Get 15% Discount on your First Order

[rank_math_breadcrumb]

Wk4_415

Need help with a question

Due 9/1/2024

The health care organization IT staff has notified the CISO that one of the new NewTab iPads® has been misplaced, though it is not known if it was lost or stolen. The NewTab information system does not have a mobile device management capability that could track and wipe the device before the sensitive data on the device can be compromised.

Refer to the
NewTab Project Profile as you complete Parts A and B below.

Part A: Create an Incident Response Plan

Create a 4- to 4.5-page incident response plan (IRP) specifically for the NewTab missing iPad incident, based on the 4 major components of incident response. Include the following in the IRP:

· Introduction

· Bulleted list of key stakeholders on the health care organization’s Response Team for the NewTab information system

· Bulleted list of compliance/regulatory requirements with respect to the health care organization and NewTab information system

· Component 1: Discovery, including the following:

· Events that should be logged and monitored with respect to the NewTab information system

· How the lost or stolen iPad® incident was discovered and reported

· Component 2: Escalation, including the following:

· Bulleted list of what triggers an event into an incident with respect to the NewTab information system

· Bulleted list of the severity of impact

· Summary of the steps for escalating the NewTab incident

· Component 3: Response, including the following:

· Summary of the planned response for the NewTab incident, including the following:

· Response to the notification of the NewTab incident

· Notification of applicable members on the Response Team

· Summary of the response

· Component 4: Reporting and Lessons Learned, including the following:

· Summary of who participates in the lessons learned for the NewTab information system incident

Part B: Create a Penetration Testing Agreement

Based on the recent incident with the NewTab information system, the CISO has been tasked with hiring a vendor to conduct independent penetration testing on the NewTab information system.

A penetration test agreement is very important to ensuring that both parties, the penetration tester and the client (your company), understand the purpose and scope of the penetration test.

 

Create a 2- to 3-page penetration testing agreement for the NewTab information system with the major sections listed below. Include the purpose and examples for each section.

· Scope for testing of the NewTab information system, including the following:

· Compliance/regulatory requirements

· Internal or external testing or both

· Technical testing

· Physical security testing

· Threat identification (i.e., who and what are the threats to the NewTab information system)

· Legal issues that must be considered

· Components to be tested, including the following:

· Gathering publicly available information

· Network scanning

· System/application scanning

· Privilege escalation

Share This Post

Email
WhatsApp
Facebook
Twitter
LinkedIn
Pinterest
Reddit

Order a Similar Paper and get 15% Discount on your First Order

Related Questions

The Equifax Data Breach

Briefly explain what the Equifax data breach was, why it happened, and why it was important. You should mention that Equifax failed to protect personal data, discuss the ethical and security issues involved, and explain what companies can learn from the incident. Please see attached documents. 

Reflection on Big Data and AI

please see attached DAT 260 Module Five Journal Guidelines and Rubric Overview In this journal assignment, you will reflect on key concepts covered in this module. This assignment directly supports your work in Project Two, which is due in Module Seven. Directions In a well-crafted journal entry, address the following:

Disaster Recovery

  Questions: Research the network and server outage problems experienced during a previous man-made or natural disaster and answer the following questions: What parts of the infrastructure was impacted? How were the networks recovered? How redundancy could have mitigated the impact of the disaster?

Network Design and Plan Purpose

Please review attachment Mod 4 Project: Network Design and Plan Purpose In this module, we will introduce a course design project that will be completed in four parts during the course. This project provides you an opportunity to solve a comprehensive problem in firewall and virtual private network (VPN) implementation

Memecoins & Stablecoins Development

Please take a look at the attachment. Lab #3: Blockchain-Based Ecosystems: Memecoins & Stablecoins Development, Attack Simulation, and Auditing Lastname: ______________ First name:____________Date_______ TA_Prove_ Yes/No 1. Overview This lab guides students through designing, implementing, deploying, testing, and auditing a simple memecoin (ERC‑20) and a minimal ecosystem around it (liquidity pool,

Blockchain Presentation

presentation about a blockchain Term Project CIS 5730- Blockchain Application Project Guideline Part ii–Presentation Along with the project you will present what you did to the class in a short presentation. If you want, you can demonstrate the project, or just present an overview of what you did. Presentations should

Network Threats

  Questions: Below is a list of common network attacks: Distributed Denial of Service (DDoS) DNS poisoning ARP poisoning Domain hijacking MAC flooding MAC cloning Man-in-the-Middle Explain two of these network attacks and discuss methods/techniques for protecting the network against them.

Best Practices for Role-Based Privilege Management in Databases

  Research the best practices for managing and securing role-based privileges in databases and address the following questions in your discussion post:  What are the key challenges in managing role-based privileges, and how do they impact database security? Can you provide a real-world scenario where poor role-based privilege management led

Computer Science Cloud Computing assignment

Please see attachment for details 4 [ Note: To complete this template, replace the bracketed text with your own content. Remove this note before you submit your paper.] Cloud Computing Evaluation Paper 1 Cloud Computing [Differentiate between cloud computing models and their uses. What are the different types of deployment

Computer Science- Python Python Programming Assignment

Computer Science Python Programming Lab assignment help. Design a Python program that calculates a credit card customer’s minimum payment based on their balance. Please use If Else and elif statements in your code. You must add comments in your code. Please round the minimum payment to two decimal places using

Blockchain Application

I need help with my coursework project. Let me know if you need any help from me.  Lab 2: Blockchain-Based Academic Credentials Lab Lastname: ______________ Firstname:________________ 1. Overview AETHELRED UNIVERSITY Registrar’s Office wants to start issuing a digital transcripts and diploma for graduating students. You are called to build the

LOREM, IPSUM

The ability to develop a risk register is a skill needed by all cybersecurity leaders when assessing cybersecurity risks. A risk register provides a detailed listing of known risks as well as quantitative or qualitative assessments of those risks, resulting in the prioritization of action.

Virtual LANs

  Questions: A VLAN allows different devices to be connected virtually to each other as if they were in a LAN sharing a single broadcast domain. 1. Why a network engineer would want to deploy VLANs? 2. How do VLANs improve network security?

compliance and rules to follow in cybersecurity.

Follow the attached instructions to complete this work. Note: Make sure to follows rubric or aligns with Rubric. Unit 8 Assignment Directions: Case Study Review the following hypothetical case study. Consider the big-picture ideas and the specific concerns. Make use of the key terms and concepts from the readings in

Discussion on data ( computer science)

Follow the attached direction to complete this work Unit 7 Discussion   Overview Consider this scenario: PQR Corporation provides facial recognition technology to customers. Its products include customer access to consumer electronics as well as mass surveillance capabilities through networked camera systems. While operating legally, PQR has maintained a low

Computer Science – Machine Learning Python Programming Assignment

Assignment Help. Please don’t forget to add comments in the code Page 1 of 3 NorQuest College – CMPT 1011: Lab Assignment 5 CMPT 1011: Introduction to Computing Lab Assignment 2: Variables, mathematical operations and data types Value This coding challenge is worth 3% of your final grade. Background In